In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:

https://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Configuretimestamprecognition
'Specify how far (how many characters) into an event Splunk software should look for a timestamp.' since TIME_PREFIX = ^ and timestamp is from 0-29 position, so D=30 will pick up the WHOLE timestamp correctly.
Reta
7 months agoBong
7 months agoLorrie
7 months agoMargurite
7 months agoChantay
7 months agoTabetha
8 months agoRose
8 months agoLino
8 months agoKattie
8 months agoThurman
9 months agoAretha
9 months agoVal
9 months agoPaola
9 months agoKarol
9 months agoGwenn
11 months agoBarney
11 months agoDalene
10 months agoAlesia
11 months agoAleisha
11 months agoQuentin
10 months agoSilva
10 months agoRusty
11 months agoAdelle
12 months agoClaribel
11 months agoMaile
11 months agoFlorinda
12 months agoGeoffrey
1 year ago