Anything written by a script to stdout is indexed as a raw event by Splunk. You can use props.conf settings to extract fields from the event. By default, Splunk will extract key and values that are in key=value format, so perhaps your PS script could do that.
I go with the default indexing of raw.
However, I had to change my output from key1=value1,key2=value2,key3=value3 (no space after comma) into key1=value1, key2=value2, key3=value3 (space after comma)
Anything written by a script to stdout is indexed as a raw event by Splunk. You can use props.conf settings to extract fields from the event. By default, Splunk will extract key and values that are in key=value format, so perhaps your PS script could do that.