Our scenario is like we are having multiple Universal Forwarders forwarding data to Splunk Enterprise through One Way, in between the UF's and Splunk Enterprise there is a Proxy server which carries the TCP packets from Multiple UF's and the Splunk Enterprise. When the data reaches the Enterprise it will shows the host IP of the Proxy Server address, so all the forwarded events will be treated as the events from the Proxy server, is there any way we can get the host details/IP address of each sources(UF's).
... View more