I need to process a syslog feed, but only keep certain hosts, and throw the rest away.
I first setup the feed to process syslog and set the host to the incoming device, and everything looks ok.
However, once I add the piece to parse the syslog, the naming of the host reverts back to the name of the server where the forwarder is running (running a heavy forwarder). I'm not sure why that is happening. Here are my props.conf and transforms.conf: