Preserve TCP Source IP Metadata for Syslog Events Before Ingester Parsing SummaryThe Securonix Syslog Connector should preserve the TCP peer/source IP received by syslog-ng and make it available as event metadata to the Ingester, parser, enrichment engine, and normalized event fields.Current behaviorUnix/Linux events are received over TCP syslog and parsed correctly. However, the TCP source IP visible at the collector is not written together with the raw event.An isolated test using the same syslog-ng binary confirmed that ${SOURCEIP} is available at the collector layer, but this metadata is not preserved in the event written to the Ingester staging path.Business impactThe current behavior affects asset identification, enrichment, searches, correlation, investigation, reporting, and coverage validation for Unix/Linux sources.The impact is greater when a source sends localhost as its syslog hostname:devicehostname=localhostipaddress=UNKNOWN In that scenario, the parser has no reliable identifier to determine which system generated the event.This affects multi