Put the appropriate time zone name on each server. Splunk knows its own time zone and will make the necessary conversions.
Ideally, each event's timestamp includes a time zone indication, but it appears your event timestamps do not.
The next best option is for the UFs on each server to have a TZ setting in the local props.conf file. This time zone value is forwarded to the indexer so it can convert the timestamps properly.
Thanks for your quickly response @richgalloway