Check the timezone configuration on your host and on your Splunk instance. Most likely the time zone is getting picked up as HST. You can change this in the props.conf for your sourcetype also as 'TZ = XXXX' directive.
http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/Applytimezoneoffsetstotimestamps?r=searchtip
Are your transforms getting applied at index time, or only search time? The Cisco app does have indexer side requirements, so if you dont have the TA installed in the right locations, it wont index and parse correctly.
Additionally, if this is only effecting a subset of your hosts, have you confirmed that they are logging in the same format as the hosts that are working correctly?
HST is our correct timezone. Unfortunately the problem is some of my logs show "Host=HST" instead of "Host=X.X.X.X".