I have a datetime SQL column that I am indexing with the DBX app. I am trying to figure out the correct timestamp format to use for an output like: 1355960605.253
This looks like epoch time to me. If it is, then Splunk will figure it out properly. You could also put this in props.conf
If you want to give Splunk a little more help, you might add a TIME_PREFIX setting and MAX_TIMESTAMP_LOOKAHEAD = 20
MAX_TIMESTAMP_LOOKAHEAD = 20
Refer to Configure timestamp recognition in the manuals for more info.