Are you not using the Splunk Add-on for Microsoft IIS to parse your IIS events ? https://splunkbase.splunk.com/app/3185/
I would assume that you are.
I've been using this in the past and I never had to make any customizations to make things working.
From the Addon, I see the props.conf have the following stanza:
But in your settings, I see you have additionally defined LINE_BREAKER, EVENT_BREAKER etc. rules.
I'd suggest to use the default settings that come out of the box with Add On and it should work smooth.
Please accept as answer if this post responds your query