Source usually correlates to a specific filename. In /usr/informix/mycertaindirectory do you have 3,000+ distinct files?
And when you say 'logs from Informix DB' do you mean the database transaction logs (the Informix physical log and logical log) or do you mean textual log files created by the Informix server process?
A common question that comes up is feeding database transaction logs into Splunk. Because most database transaction logs are in an opaque binary format, and because most database vendors are unwilling to provide documentation about that format, Splunk cannot directly ingest database transaction logs and make sense of them.