Try using %3N
"For GNU date-time nanoseconds. Specify any sub-second parsing by providing the width: %3N = milliseconds, %6N = microseconds, %9N = nanoseconds."
https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Configuretimestamprecognition
... View more