INDEXED_EXTRACTIONS is attempting to use the first line as the header (the column/field names). That is why you are only seeing 3 events. You can use DELIMS here but in Splunk 6 we introduced:
INDEXED_EXTRACTIONS = csv
specifically so you don't have to define the fields in DELIMS. We attempt to automatically read the first line of the CSV (usually the header) and create index-time fields.
So, if the file has no header, you can use INDEXED_EXTRACTIONS = csv with the
FIELD_NAMES option:
http://docs.splunk.com/Documentation/Splunk/latest/Data/Extractfieldsfromfileheadersatindextime
OR use props/transforms with DELIMS but you cannot mix the two.
... View more