I set the custom time to June 14 11:48:00 -> June 14 11:48:05. I then click on search and the log info is shown but the search on the screen states "198 events from 11:48:00 AM to 11:48:05 AM on Sunday, June 13, 2010". I assume I need to set some sort of locale ? I am in New Zealand.
This sounds like a bug to me.
Depending on the source of your data you need to set TZ appropriately, both on the input (props.conf), and in your environment ("export TZ=My/TimeZone")
http://en.wikipedia.org/wiki/List_of_zoneinfo_time_zones
Splunk will then search correctly with your given offsets, unless something extra-special is happening.