Hope this helps. This scenario is for Splunk but same can be applicable for other syslog servers forwarding syslog data to McAfee SIEM.
Many thx for this document
Did you set the individual data sources up as Child objects or Clients of the Forwarder?
Can't remember it was year ago. Sorry