_time is normally the parsed timestamp from a message, and it is adjusted for timezone.
If for some reason Splunk has got the wrong timezone set for a particular input, this can be corrected/specified in props.conf
[spec]
TZ = UTC
will instruct splunk to treat events of type spec as being in the UTC timezone. spec can be one of either sourcetype , source::your_source_name or host::your_host .
See the following docs for more info;
http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutconfigurationfiles
/K
... View more