So, the reason was that I live in Europe, and time that I was sent to the Splunk was divided not dot (.) , but comma (,), so I had to rebuild project with some changes to date format that sending to the Splunk (timestamp) and it resolved problem.
Also all payload data is covered with double quotes and every single field inside the received file (in my case JSON) will be recognized as only 1 string.
So, the reason was that I live in Europe, and time that I was sent to the Splunk was divided not dot (.) , but comma (,), so I had to rebuild project with some changes to date format that sending to the Splunk (timestamp) and it resolved problem.