In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:

https://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Configuretimestamprecognition
'Specify how far (how many characters) into an event Splunk software should look for a timestamp.' since TIME_PREFIX = ^ and timestamp is from 0-29 position, so D=30 will pick up the WHOLE timestamp correctly.
Reta
4 months agoBong
4 months agoLorrie
4 months agoMargurite
4 months agoChantay
4 months agoTabetha
5 months agoRose
5 months agoLino
5 months agoKattie
5 months agoThurman
5 months agoAretha
6 months agoVal
6 months agoPaola
6 months agoKarol
6 months agoGwenn
8 months agoBarney
8 months agoDalene
7 months agoAlesia
8 months agoAleisha
8 months agoQuentin
7 months agoSilva
7 months agoRusty
8 months agoAdelle
9 months agoClaribel
8 months agoMaile
8 months agoFlorinda
9 months agoGeoffrey
9 months ago