Hi @vrmandadi
You can run this to check for time skew among your instances -
| rest /services/server/info | eval updated_t=round(strptime(updated, "%Y-%m-%dT%H:%M:%S%z"), 2) | eval delta=now()-updated_t | table serverName, updated, delta | convert ctime(updated_t)| rename updated as "Local Time on Server on Request" delta as "Offset - Time in Seconds"
And if you find some gap here, you might want to set your server clocks
Also check -
https://docs.splunk.com/Documentation/Splunk/7.3.0/DistSearch/Troubleshootdistributedsearch
... View more