In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:

https://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Configuretimestamprecognition
'Specify how far (how many characters) into an event Splunk software should look for a timestamp.' since TIME_PREFIX = ^ and timestamp is from 0-29 position, so D=30 will pick up the WHOLE timestamp correctly.
Reta
5 months agoBong
5 months agoLorrie
5 months agoMargurite
6 months agoChantay
6 months agoTabetha
6 months agoRose
6 months agoLino
7 months agoKattie
7 months agoThurman
7 months agoAretha
7 months agoVal
7 months agoPaola
8 months agoKarol
8 months agoGwenn
10 months agoBarney
10 months agoDalene
8 months agoAlesia
10 months agoAleisha
10 months agoQuentin
8 months agoSilva
8 months agoRusty
10 months agoAdelle
10 months agoClaribel
9 months agoMaile
9 months agoFlorinda
10 months agoGeoffrey
11 months ago