The only think I can suggest is there may be a wrong timestamped event on EventID=4725 or 4722. Since you are using "latest(_time) as _time" it will try to get the latest event sorted by _time. Please check if the correlation search that creates mismatched times has wrong timestamped data. You should be see this by running these searches and checking _time field.
... View more
Can you please suggest CIM mapping and what Data model we can use for canary app. https://splunkbase.splunk.com/app/3980/ https://splunkbase.splunk.com/app/3981/
... View more