Actually, the timestamp shown does have TZ information. The Z at the end of the timestamp means "Zulu time" or UTC. Splunk should understand this, but I suspect it's having problems with the subsecond resolution (do you really need 6 digits of subsecond precision?!?). Look in etc/datetime.xml and you'll see the automatic extractions.
... View more