No matter what format I attempt to force upon historical timestamps:
Feb 11, 2004 01:23:45
splunk ignores years that fall before 2006 while the rest of the timestamp is preserved. The current year (2011) is substituted for years <= 2006.
Is this a configurable parameter/range I'm missing?
Yes, your dates are being restricted by the default MAX_DAYS_AGO setting in props.conf. The default is 2000 (days), which currently puts the limit at September of 2005.
View solution in original post