Thanks a lot for the information. We also saw the metadata option but what happens is that it will only add the metadata to one event. My understanding is that Splunk first splits the file into events using the LINE_BREAKER, and only then applies the field extractions (just my guess as this is not really explained anywhere), so we did not manage to extract something that is applied to all the events. But we do think that this is something that should be allowed to configure somewhere.
... View more