If doing this at index-time really is requirement, you can always use a report on the part of the event that starts with auth_source=
the report option in your props file associated with your sourcetype the extracts at search time the pairs separated by the = sign
Check this answer for reference 🙂
https://answers.splunk.com/answers/9853/multivalue-field-regex-question.html#answer-9875
... View more