I'm not clear where and when the src field gets its value for the WinEventLog data.
This should be happening in the Splunk_TA_windows app. Check the props.conf and transforms.conf in the default directory.
HI danielbb,
This question doesn't seem a Splunk question, could you give more details?
Ciao.
Giuseppe