As you can see in the screenshot, if Windows TA is enabled (https://splunkbase.splunk.com/app/742/), it shows the event in the time field and time in the i field. Why could this be?