This is a clear indication that the events that you are sending into Splunk are mis-timestamped. Splunk will only allow timestamps to deviate from "now" by a few days forwards (default is 2) or backwards (default is 2000). If the timestamp that splunk identifies inside of your event it outside of this window, the event will be given
http://docs.splunk.com/Documentation/Splunk/6.3.3/Data/Configuretimestamprecognition#Edit_timestamp_properties_in_props.conf
You need to take a look at your timestamp configuration definitions in props.conf and compare them with your events. If this is correct, then you need to make sure that you do not have a timezone issue.
... View more