timechart [stats count|eval app=$A$|eval search=case(app=="*","span=30m count by B",app!="*","span=30m count by C")] is not work after upgrading splunk from 8.0.6 to 8.2.5.
You already asked this question. https://community.splunk.com/t5/Splunk-Search/How-to-correct-timechart-after-upgrading/m-p/593883#M2...
Something similar to this appears to work with 8.2.5 (and other versions). Please provide more details e.g. our dashboard SimpleXML as there may be something other than the timechart command not working.
Can you provide more context? The search you provided isn't a functional standalone search in any version of Splunk.