There is a closed thread here:
Where @andrewkroh says, "I would recommend running all your systems with UTC time..."
Does that mean all systems in the Elastic stack? Or all systems that we'd ever want to ingest logs from? If the Elastic stack needs to be in UTC time, we can head in that direction, but we are a MSP for clients in multiple timezones and as such cannot control which time zones the customer systems are in.