In a passthru route, Cribl is adding the Cribl Worker ip address on the host field before sending to Splunk. How that can be avoided? This fields already comes from the source with different values.
Is your source is syslog? Cribl will parse the syslog header and extract the
host field. If you’re looking for the ip of the sender, you can find that in