I have a self-service dashboard running in our Splunk Cloud V6.2 environment which displays indexed amount over time from a summary index that's populated by a saved search. Users have noticed that the chart seems to be sorting by month & day but ignoring year. Is this related to the latest date processing bug that was identified at the end of last year? I went through the remediation steps but maybe something was missed.
I am using this search:
index=corpsplunklicensedetails $indextok$ | eval Volumegb = round(volumegb,3) | chart sum(Volumegb) as "Amount Indexed (GB)" by day, origindex