In my test with these sample events, the following seemed to work:
LINE_BREAKER = (<94>1)(\s)
SHOULD_LINEMERGE = false
Explanation from our props.conf docs:
The regex must contain a capturing group -- a pair of parentheses which
defines an identified subcomponent of the match.
Wherever the regex matches, Splunk considers the start of the first
capturing group to be the end of the previous event, and considers the end
of the first capturing group to be the start of the next event.
The contents of the first capturing group are discarded, and will not be
present in any event. You are telling Splunk that this text comes between
lines.
... View more