I don't think this answers the original poster's question. The OP wanted to know if and how Splunk treats values which have embedded delimiter in them
such as
value1, value2, "value3a, value3b", value4
The OP would like to read the entire "value3a, value3b" as one field value.
... View more