I would like to know can I configure splunk to receive syslog in Single Input (UDP:514) with multiple host and multiple Sourcetype. If so, how can I do that?
Thanks
Yep. You want to look at doing a host override and a sourcetype override. Well, several of each, probably.
These links should get you started: