I found answer from http://forums.iis.net/p/1170786/1954080.aspx created on source machine a register "Key" at
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Microsoft-Windows-PrintService/Operational
and everything worked properly.
... View more
I have already asked this question long ago, but still no correction from Splunk team.
See some workarounds on this:
http://splunk-base.splunk.com/answers/40985/time-zone-recognition-still-doesnt-work-after-editing-propsconf
... View more