Json filter message filed

then you can tag them on ingest based on the source host, depending on how you receive them. for example if you receive with syslog, you can tag them in the input section