Why splunk won't correctly recognize this timestamp?
120129092233
my props.conf
TIME_FORMAT=%Y%m%d%H%M%S
TIME_PREFIX=^
example of source log:
120129092231;field1 field2 field3
120129092232;field1 field2 field3
120129092233;field1 field2 field3
try:
TIME_FORMAT=%y%m%d%H%M%S
TIME_PREFIX=^
Works! Yes, y% is for year without century like in my log.
Splunk rocks!!
Your time_Prefix stanza looks correct but I dont think you need the prefix. Not sure if the docs will shed some light but you can fine them here: http://docs.splunk.com/Documentation/Splunk/latest/Data/
ConfigureTimestampRecognition