Surprisingly, it seems to work if I add a TIMESTAMP_FIELDS line to the bottom of the source type section like: [LOGDATA]
EXTRACT-LOG = ^(?<domain>[^,]+),(?<host>[^,]+),[^,]+,[^,]+,[^,]+,(?<timezone>[^,]+),(?<sourcename>[^,]+),(?<TEXT>.+)$
TIME_FORMAT = %m/%d/%Y %H:%M:%S
TIMESTAMP_FIELDS = _time, timezone Splunk must create the _time field and then update it with the timezone?
... View more