Can you post your props.conf
which is located on your indexer(s) under $SPLUNK_HOME/etc/system/local
?
We are using the settings from the /opt/splunk/etc/system/default/props.conf
Did you copy and paste the default settings to your local settings?
I would recommend you create a new props.conf
under $SPLUNK_HOME/etc/system/local
[source::YOUR_SOURCE_PATH]
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S,$3N
MAX_TIMESTAMP_LOOAKAHEAD = 30
LINE_BREAKER = \[\d\/\d+\/\d+\s\d\:\d+\:\d+\:\d+\sEDT\]
SHOULD_LINEMERGE = false
TRUNCATE = false