The messages at the top of the screen populates with the following error:
lookup_expander: Some extra fields were present in the input CSV
I want to keep the extra fields in my lookup but I don't want my users to see the error message
Any ideas on what I should do?
Custom fields in asset and/or identity tables were prohibited by design beginning in Enterprise Security 2.2, which contained performance optimizations for asset and identity correlation.
However, we now have a patch that provides custom field support for Enterprise Security 2.4. To obtain it you should contact Support to open a case. Provide your exact Splunk and app version information, and we should be able to help.