I've halfway figured this one out. The searches span -7d to now and I'm backfilling 7 days. Splunk is using the info_min_time (first event used in stats) as the timestamp for the summary event.
Is there a way to get Splunk to use info_max_time as the summary timestamp? In the meantime, I am using a workaround of
| rename info_max_time as _time
Would be nice to be able to tell Splunk to use info_max_time as the timestamp when writing to summary.