In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:

https://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Configuretimestamprecognition
'Specify how far (how many characters) into an event Splunk software should look for a timestamp.' since TIME_PREFIX = ^ and timestamp is from 0-29 position, so D=30 will pick up the WHOLE timestamp correctly.
Reta
9 months agoBong
9 months agoLorrie
9 months agoMargurite
10 months agoChantay
10 months agoTabetha
10 months agoRose
10 months agoLino
11 months agoKattie
11 months agoThurman
11 months agoAretha
11 months agoVal
11 months agoPaola
12 months agoKarol
12 months agoGwenn
1 year agoBarney
1 year agoDalene
1 year agoAlesia
1 year agoAleisha
1 year agoQuentin
1 year agoSilva
1 year agoRusty
1 year agoAdelle
1 year agoClaribel
1 year agoMaile
1 year agoFlorinda
1 year agoGeoffrey
1 year ago