Hello,
please vote this idea : https://ideas.splunk.com/ideas/EID-I-1034
Apart from using a 'host' field to store information about host where the issue originates from, it would be good to introduce a special field (eg. similar to _indextime) which would store the forwarder's IP or hostname visible from the network's point of view.
Thanks.