Hi jeffmec,
I haven't seen the app itself, but from the symptoms you describe I'd bet that the app does some internal routing of events. Check the app's (or corresponding TA's) transforms.conf on the indexer for some stanzas that do sourcetpye rewriting based on regular expressions:
[some_stanza_name]
REGEX = ^.*someregex.*
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::sophos:xg:IDP
Detailed info on the topic: http://docs.splunk.com/Documentation/Splunk/latest/Data/Advancedsourcetypeoverrides
Best
Oliver
... View more