Hello fellow ES 8.X enjoyer.
We have a few Splunk Cloud customer that got upgrade to ES 8.1. We have noticed that all the drill down searches from Mission Control use the time rage "All time", eventhough we configured the earliest and latest offset with $info_min_time$ and $info_max_time$:
After saving the search again the problem vanished. I also created a new search and worked correct immediately.
It worked before the update for the existing searches and stopped working after the upgrade.
Anybody else with the same experience?
Best regards
we are experiencing the same issue, subscribing to this thread in case anyone finds a solution
Try save again exist drill-down search (even without real changes) or create form scratch. After the „changes” tokens $info_min_time$ and $info_max_time$ start working good.