We have our InfoBlox appliance set to use UTC. However, Infoblox logs in Splunk are showing as -0400, but they should be -0500. Where do I adjust this? I'm not seeing anything in props.conf that stands out.
What version of Splunk is running in your environment? Is the forwarder that is picking up the data from infoblox the same timezone as your indexer / search head / user searching?
If all is the same, there are props.conf settings to force a timezone.