Prior to upgrading to Splunk 6 I had my props.conf configured to specify TZ's for certain host. Since upgrading to splunk 6 I noticed some entries are displaying and ordering in EST and others are still in GMT. Source of the entries are the same, syslog and in this instance I am not using splunkforwarder I am using syslog to forward to indexer. Props.conf I edited is in $SPLUNK_HOME/etc/system/local
I figured out my problem. I modified format of syslog then edited props.conf to add "%z" to TIME_FORMAT in props.conf:
TIME_FORMAT = %b %d %H:%M:%S %z