I am trying to match my IIS server time with my Splunk server time but always there is a difference of 3 hours.
and it doesn't come as a real-time alert.
You can redefine time in the search by adding/subtracting seconds. E.G.
youbasesearch | eval _time=_time-10800
or +10800