I believe you are misunderstanding how the user's timezone normalization works.
On the Events tab, find the Raw/List/Table link on your Search Head that is just under the timeline graph, just above the thin line that marks where the search results are shown, just to the right of the fields area, but still the farthest thing to the left on that line. Make sure it is set to List . This will add a column to your search results called Time which will show you each event's _time value formatted for the Time zone setting in your user profile. You may be confused because the timestamp shown inside the raw event text will never change and will always be exactly the way it was when the thing that generated it sent it to splunk. This setting also effects the way the Timepicker interprets relative times (e.g Yesterday ).
... View more