Need to know what is being used to send the data (Splunk UF, syslog, etc..).
If using Splunk, show the outputs.conf stanza's
What are the settings of the input used to receive the data, show the inputs.conf stanzas
Great, however, what I need to know is How are you sending them? Splunk UF or Syslog?
What does the outputs.conf look like?
How are you receiving them? what does the inputs.conf look like