Samples are collected and later manually entered into Splunk. I am interested in the time the sample was tested, not when it was uploaded into Splunk. There is a field called Manual Time with the format in "%H:%M:%S %p".
I wrote a search based on other answers that can work using the _time field but it does not seem to work for the ManualTime field.
The following code results in having a ManualTime and nowstring time listed in the same time format.