Hi reswob4 and welcome,
I suggest that you make yourself familiar with how the indexing process in Splunk works: https://wiki.splunk.com/Community:HowIndexingWorks
Timestamping occurs after the first parsing instance (merging pipeline), which is in your case the indexer (if there is no HF in between).
Timestamping settings can not apply on a Universal Forwarder and as such must be configured on a Cluster Master (in case your indexers are clustered).
Also, you don't want to upload anything to an IDX directly. Usually, your UI on an IDX isn't even enabled. It's a best practice to forward all your SH data to the indexing layer and as such, you could do test uploads on your SH.
Skalli
... View more