You're thinking in wrong order. That's why I'm saying it's not possible with Splunk alone. If you don't know this one, it's one of the mainstays of understanding of Splunk indexing process- https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590774 As you can see, line breaking is one of the absolute first things happening with the input stream. You can't "backtrack" your way within the ingestion pipeline to do SEDCMD before line breaking. And, as I wrote already, it's really a very bad idea to tackle structured data with regexes.
... View more