Probe identification inside regular Eve-log

Hello,

Is there a way to identify the suricata probe inside eve-log? I mean, imagine you have the raw eve-logs of many suricata probes all mixed together, but you want a parameter to identify which probe wrote that event.
I have seen that there is a parameter “identity” but it only works if syslog type log, but I am using regular. Is there anything similar in regular type?

Thanks in advance.

Suggest setting the sensor-name configuration value in each Suricata deployment’s configuration file. The sensor-name value is contained in the alert as the host element