Why does the Splunk Add-on for Qualys map the endpoints with vulnerabilities to dvc instead of dest?
Per the CIM manual:
dvc The system that discovered the vulnerability.
dest The host with the discovered vulnerability.
It's wrong to do so; there is a bug on this.