For how Splunk breaks up streams of "stuff" you'll want to refer to segmenters.conf
Here's a link to the configuration file for segmenters.conf. You may also fine it useful to read more explanation about segmentation and segmentation types. Those two links should give you what you need - a list of which characters do what things by default when Splunk breaks up events into fields and segments.
... View more
It is true that inputlookup and inputcsv use files on the Splunk server. However, power users can upload files into Splunk using the lookup capability, and therefore use these commands. You don't have to be a Splunk admin.
... View more