well, I assume that the starting H:M:S.ms timestamp exists in all messages - and is correct. If that is the case, then both the TIME_FORMAT and TIME_PREFIX are wrong.
[sourcetype]
TIME_PREFIX = ^
TIME_FORMAT = %H:%M:%S.%3N
MAX_TIMESTAMP_LOOKAHEAD = 15
TZ = US/Eastern
Normally you'd use the sourcetype as a base for your timestamp extraction, so if you monitor multiple logfiles in the same directory in the same stanza, you can only set one sourcetype for them all. So if timestamps differ between log files, this might not be correct.
If you could configure your logging to also include the date on each line, you'd be settled.
/K
... View more