Log forwarding from other SIEM to DNIF

We forwarded logs from another SIEM to DNIF Adapter.

Here the issue is it is showing only one source for all logs in collection status and we expect it should detect different sources .

Kindly suggest on this.

Regards,
Satish

Hi - looks like you would have forwarded all the logs from the same syslog server. Collection status shows the IP from where these logs are receiving. However if the log formats are correct, the appropriate extractor should get applied and logs would parse correctly.