I would like to extract timestamp from events where the leading zeros of the time format are omitted.
Most of the events have the time format like the example below, where Splunk is able to extract the correct time for the events to be 2010/03/22 11:59:49 pm.
I'm not sure this is possible. Parsing is difficult when there is ambiguity - would a time of "1111" be 00:11:11, 11:11:00 or 01:01:01?
In my opinion, this is the type of problem where for the sake of your own sanity you are far better off to try to get the source application fixed to where it either delimits Hour, Minute, Second, Subsecond or 0-fills appropriately.