There should be field called 'splunk_server', but don't think that helps with your situation.
You can process data at index time with a transform, there is more info here: http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Configureindex-timefieldextraction
... View more