Include the affected email address in the API json structure as well.
Ingesting in Splunk becomes easier when the unique account is included in the API json data structure. Otherwise you cannot tell these individual disclosures apart.

Anonymous commented
Yes, I know the email address, however directly ingesting in Splunk or ELK needs some tweaking of the json. For now, I just added '{"Account" : "", before every "Title" field. Maybe I'm being a n00b here, because I just started expirimenting with your awesome service.
Which API? If it's the one to pull back breaches for a single email address, don't you already know the email address as you've just sent it in the API request?