Hi,
It is detected correctly as separated log sources using the host names. The issue is, the source IP which in this case always the address of the relay and this can cause some issues in rules where we rely on source address. Maybe there is no easy solution for this because I don't think Qradar can parse IETF syslog where the original source address can be put in .sdata fields
Thanks
L:
------Original Message------
Hello.
I've seen this kind of issues when wrong syslog message structure was used. Maybe there is an issue with syslog header format. If format is ok, every source device log, sent from relay should be detected as separated log source by qradar, and it doesn't' matter if it is IP address or host name.
------------------------------
Gasper Hribar
------------------------------