According to Support this is bug SPL-59079 and will be fixed in 5.0.3.
I tested and despite the message saying it has no effect, it certainly does have an effect: ... | timechart minspan=30s count by ...
makes 30 second buckets on a Last 15 Minutes
search. However, ... | timechart minspan=5s count by ...
makes 10-second buckets. Case 114952 filed.
Also on Splunk 5.0.2, just in flashtimeline or charting views. "Span" is likely a time range you're running the search over - the message would not pop up or all time searches or real time searches - but any other timespan had this message appear. http://[splunk instance]/en-US/app/search/charting/?q=search%20index%3D_internal%20|%20timechart%20minspan%3D30s%20count%20by%20sourcetype&earliest=-24h%40h&latest=now&c.chart=area&c.title=&c.stack=stacked&c.split=false&c.nulls=zero&c.legend=right&c.x.title=&c.y.title=&c.y.min=&c.y.max=&c.y.scale=
Seeing the same thing in 2.3.1 on Splunk 5.
FWIW, I'm seeing this error while running reports in SoS v2.3.1 on Splunk 5.0 as well.