Good day, this does not seem related to the original question asked--thus you may want to open a new question for proper tracking.
This also seems like more of a Splunk question and not so much of a FireEye App specific question. You may want to contact your Splunk rep as well to see if they know the answer.
I can only guess that the data is being split into multiple parts due to improper line breaking? Did you try changing the format? It appears you are using JSON in the same above. Can you try to switch to TCP syslog CEF and see if you still have the same issue?
Feel free to email via Help -> Send Feedback from within the app and we can try to troubleshoot a bit as well. Hope that helps.
... View more