Thanks. I've been trying to get this working, and it seems like something is still missing. I'm getting forwarded events into Splunk, but the source host is still the computer name of my event collector, not the computers that originally forwarded the events. Any additional suggestions would be appreciated. (It looks to me like there might be a typo in your suggested props.conf file entry, I think I fixed that on my agent, but still no luck.)
... View more