In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:

https://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Configuretimestamprecognition
'Specify how far (how many characters) into an event Splunk software should look for a timestamp.' since TIME_PREFIX = ^ and timestamp is from 0-29 position, so D=30 will pick up the WHOLE timestamp correctly.
Reta
2 months agoBong
2 months agoLorrie
2 months agoMargurite
3 months agoChantay
3 months agoTabetha
3 months agoRose
3 months agoLino
4 months agoKattie
4 months agoThurman
4 months agoAretha
4 months agoVal
4 months agoPaola
5 months agoKarol
5 months agoGwenn
7 months agoBarney
7 months agoDalene
5 months agoAlesia
7 months agoAleisha
7 months agoQuentin
5 months agoSilva
5 months agoRusty
7 months agoAdelle
7 months agoClaribel
6 months agoMaile
6 months agoFlorinda
7 months agoGeoffrey
8 months ago