Pardon?
My time zone setting is "Default System Timezone", which is actually +8.
I have the simplest scenario, this event happened around 10 AM in my TZ, and was sent by the Sender from the same TZ, and Splunk host is also in the same TZ, but in the Time column I see "4/26/19 1:57:19.000 AM"
... View more