Since you have a delimiter that is separating your fields then I would take a look at the following:
$SPLUNK_HOME/etc/system/local/props.conf
[data]
REPORT-fieldextract = fieldextract
$SPLUNK_HOME/etc/system/local/transforms.conf
[fieldextract]
DELIMS = ","
FIELDS = field1,field2,field3,...field16
Remember that this field extraction happens at index time so this will only work for the latest data.
Here is a link to more information:
http://docs.splunk.com/Documentation/Splunk/4.3.1/Admin/Transformsconf
... View more