I have a problem and I can review event exists a disface between variable time extract and "_time" on SPL
Verify the time zone is set correctly in your Splunk preferences.
Verify the data is onboarded correctly. Check props.conf for the correct TIME_FORMAT setting. Add a TZ setting so Splunk knows the time zone in which the event was generated.
add on props.conf and still the problem:
...disabled=falsepulldown_type=trueTZ=America/SantiagoTIME_FORMAT = %m/%d/%Y %H:%M:%S