I'm having problems getting Splunk (through data preview) from correctly parsing the following timestamp:
2013.08.14 12:47:02:467 MST
I am using the format below but the milliseconds are ignored and Splunk shows '8/14/13 12:47:02.000 PM' instad of '8/14/13 12:47:02.467 PM'
TIME_FORMAT=%Y.%m.%d %H:%M:%S:%3N %Z