There is constant time diff (_indextime - _time) from few windows server as below, not sure what causing this and how to fix it
Thanks Giuseppe, seems to be AM/PM parsing issue. How this could be addressed?
you should see your logs and the props.conf related to your sourcetype and eventually add to it the timezone definition.
a fixed difference like this can have one of the following three causes:
In my experience the fist option is the more possible.
In this case you have to analyze your logs and the parser and change the timezone setting.