I tried also \t, "\t".
The defined fields never appear in Splunk and the first row from t...
...LAN, or MAC address is different then I don't want to dedup it. I tried defining the whole block of text as a field, but that doesn't appear to work. It seems like a field cannot include spaces.