Another method is to use the props/transforms combination that uses the comma as a delimiter. Here is an example:
props.conf
[sourcetype]
REPORT-fields = commafields
transforms.conf
[commafields]
DELIMS = ","
FIELDS = field1, field2, field3, field4, uri, field6, field7, field8, field9, date
Here is a link to more information:
http://docs.splunk.com/Documentation/Splunk/6.1.3/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles
... View more