I was having the same problem. (My Index is a windows machine if that makes any difference.)
I added this to my $SPLUNK_HOME/etc/apps/Splunk_CiscoIPS/local/props.conf
under the [cisco:ips:syslog] stanza
SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE_DATE = true
... View more