We have multiple firewalls sending syslogs to different servers to allow for the agents on those servers to forward the logs to the SIEM. The source is always the name of the server, not the name or brand name of the firewalls. It would be nice if we could change the names of the source type and agent for them so they are easier to find.