Hi @pck1983, here you can find some useful description of how Splunk manages timezones: https://docs.splunk.com/Documentation/SCS/current/Search/Timezones https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Applytimezoneoffsetstotimestamps In few words, yes, if Splunk isn't able to understand the timestamp, is uses the previous event timestamp or _indextime as _time. Splunk automatically manages different timezones so, setting the timezone in your user preferences, you can read the timestamps using the timestamp corresponding to your timezone. Ciao. Giuseppe
... View more