I have a file which contains :
Hi this is really great of you !!
My name is john, how are you
this is no one
I am appending few more lines after the last line but before that i want a single blank line to distinguish both the content as : my output should look like this :
Hi this is really great of you !!
My name is john, how are you
this is no one
Hi, this is my new line started
I am happy to know you
great people always smile
Are your lines parts of the same events ?
If the pattern is easy to recognize, I would recommend to use a sed command to add new lines characters.
| rex field=_raw mode=sed "s/mylastword/mylastword\n/g"
in both case, please read the documentation for the commands.
If the pattern is not common, then you'd better fix your source format before indexing it.
What does this have to do with Splunk? Surely you need to either specify you scenario if it is related!