From the SRX device we are sending syslogs to syslog server. however the hostname if missing only for RT_FLOW logs when we are checking on syslog server. We are not doing any kind of filtering or modification of logs. for logs apart from RT_FLOW we can see hostname in the syslog before 'RT_FLOW' field.
Here is one sample:
Apr 10 10:38:39 RT_FLOW: RT_FLOW_SESSION_CLOSE: session closed idle Timeout: 10.54.17.68/56528->10.26.124.50/161 None 10.54.17.68/56528->10.16.124.50/161 None None 17 CST000000xx7304 DD_WS mgt-out 140085954 1(83) 0(0) 213 UNKNOWN UNKNOWN N/A(N/A) eth1.12 UNKNOWN
Request you to provide your inputs asap as the security monitoring is impacted.