Hi a212830,
If you create you own source type and you use the BREAK_ONLY_BEFORE option to create a regex that will look for the two linebreaking formats:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf
Without knowing much more information on what you are currently working on, you could set it to something like:
BREAK_ONLY_BEFORE = (^*|^date)
Hope this helps, if you would like to provide some examples, I would be happy to help set up the props.conf file with you.
Regards,
Vince
... View more