Take a sample, use use the data preview to test your timestamp format extraction.
see http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/Configuretimestamprecognition
http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/ConfigurePositionalTimestampExtraction
and for the timeformat, http://pubs.opengroup.org/onlinepubs/009695399/functions/strptime.html
As first sight, Your timestamp TIME_FORMAT looks like "20120309203829.9230-050000"
-> "%Y%m%d%H%M%S.%4N%Z"
... View more