I have a distributed setup of Splunk ES, with separate SH, indexers and forwarder. I set some flows (sFlow, Netflow to forwarder). However, forwarder's IP is set in a "host" field of all logs. How can I keep the original device address (i.e. an address of a router that is sending those flows).