The event appears in search showing 15:11 as the time _time = 2016-09-27T15:11:00.999+01:00. The event actually happened at 14:11 British Summer Time which is GMT +1 which is what is shown in the raw event. I have my user settings at the correct timezone (GMT:London), my user locale is en_GB in the Splunk Cloud URL and all data from other data sources is showing up correctly in the indexes.
The data is going from a Universal Forwarder to a Heavy Forwarder (where the props.conf is set) and then on to Splunk Cloud.
I have tried adding a TZ = Europe/London to props.conf but that doesn't fix it.