There is no field in the Syslog log that can identify the group to which the device belongs

We collect incident logs in the form of syslogs. Divide equipment from different departments into different groups and manage them separately on the console. But I found that there is no field in syslog that can represent the group to which the device belongs. This leads to the mixing of logs from different groups, making it difficult for us to manage logs.