When doing field extraction, Splunk may look at fields containing commas as "multi-valued" fields - or not, depending on your configuration.
erex might not be a good choice for dealing with this, because it uses commas to separate the sample values. For the example that @garywiner provided, this will work
yoursearchhere
| rex field=_raw "Name=(?<lastname>.+?)\,(?<firstname>.+?)\;"
This creates two fields, lastname and firstname... You could use a similar regular expression in a props.conf EXTRACT to make these fields permanent.
... View more