Do you have Splunk UF's that are running in a load-balanced manner and/or
ingesting other host data (ie. central syslog server)?
Take advantage of Splunk's built-in meta tagging. This meta tag can be used with
multiple key::value definitions.
Navigate to ~/etc/system/local within