Does the older logs in JST time is still remains in same format (JST) OR it configures to UTC timezone ?
Splunk has no reference back to the current state of the original source of any data. All it knows about is what it already has in its possession. This is why it is important to get the data (and extraction rules) right in the indexing input/parsing phases. Once you have it, short of re-importing (and hence hitting your input allocation), you can do nothing about historic data.
Changing the configuration of the Cisco device has no effect on logs already in Splunk,