Splunk isn’t recognizing the date from the opsec.logs since the date is being sent in a localized format
This can be resolve by modifying DATESTAMP = epoch (“unix”) and by doing this don't need to set TZs. You will need to edit DATESTAMP properties under fw1-loggrabber.conf file so that it is indexed properly.