How do convert the IIS log timezone (GMT) to the local time in splunk?
Are you using IIS W3c? if so check this: http://answers.splunk.com/questions/1425/timezones-iis-w3c-extended-logging-why-dont-they-work
Otherwise check: http://www.splunk.com/base/Documentation/4.1.5/Admin/Applytimezoneoffsetstotimestamps
cheers!