For some reason, after upgrading Splunk to 7.1 some searches no longer return the results for certain days; instead of returning the right day's results, it repeats old dates. If I click a date like 4/4-4/5 in search for the last 30 days, it will return results from 4/19 instead. If I add a filter to host, then everything works correctly and I can see results. I can also search the entire year and all of the results are returned as well.
There's nothing special going on aside from a few field extractions here and there. Is this a known bug? I thought at first it may have been related to cached JS files locally but I've cleared my cache and also tried a number of variations to try to fix this to no avail. The only thing that consistently works is zooming out to the year, or setting the exact host. This also affects exporting the results among other things.
... View more