Is ANY of this behavior than Splunk on any other platform?
1) What sourcetype are your syslog files classified as?
If they aren't syslog, you should add them as inputs and explicitly set the sourcetype to syslog.
2) This is probably a result of #1. Otherwise, you can explicitly specify the timestamp format in props.conf with TIMESTAMP_CONFIG
3) cycle redundancy check is not windows related it sounds.
... View more