We have a simple xml dashboard that has many charts that reference saved searches that are run every night at 3am. Since upgrading to Splunk 7.1.1 when we reference the saved search in our dashboard the search that is used is NOT the most recent saved search it is the oldest. This was not the behavior in Splunk 7.0.x.
[DatesPrevious30Days] run_on_startup = true alert.track = 0 cron_schedule = 0 3 * * * dispatch.earliest_time = -30d@d dispatch.latest_time = @d enableSched = 1 search = index=nmi_main source=netmotion sourcetype=nm_session \ | fields _time \ | stats min(_time) as firstTime max(_time) as lastTime \ | eval totalDays=round((lastTime-firstTime)/86400,0) \ | eval firstTime=strftime(firstTime, "%a %b %e, %Y") \ | eval lastTime=strftime(lastTime, "%a %b %e, %Y")
I am not sure on the issue, as we are still using 6.64; but did you happen to use the below for calling the saved search and try it?
Before applying this on the dashboard, you can try running this on the search bar, and see if it is taking the latest savedsearch result,