My problem is that Splunk
1. writes the first 257 lines of the event
2. writes the next event that happends to have the same timestamp
3. finishes off the writing the remaining 104 lines of the first event as a new event
I am not sure if having 360 lines in an event causes a bottle neck or if I need to modify a file somewhere.