Splunk Enterprise

Duplicate values in Cisco DNA logs

AlonsoHM
Loves-to-Learn Lots

Thank you in advance for your help community

I performed the integration of Cisco DNA to Splunk

  • Created my "cisco_dna" index on my Heavy Forwarder
  • I installed the Cisco DNA Center Add-on on my Heavy Forwarder (https://splunkbase.splunk.com/app/6668)
  • Added the account in the add-on (username, password, host)
  • Activated all the inputs:
    • cisco:dnac:clienthealth
    • cisco:dnac:devicehealth
    • cisco:dnac:compliance
    • cisco:dnac:issue
    • cisco:dnac:networkhealth
    • cisco:dnac:securityadvisory
  • I also created my “cisco_dna” index on my Splunk Cloud instance.
  • Installed the Cisco DNA Center App (https://splunkbase.splunk.com/app/6669)
  • Done, I started receiving logs in Splunk from Cisco DNA

But when validating the dashboards in the APP and reviewing the search results I noticed that the values of the fields are duplicated.

AlonsoHM_0-1733266402127.png

Even if I apply some dedup to any of the fields, the result is “only one duplicate value”.

AlonsoHM_1-1733266540326.pngAlonsoHM_2-1733266625761.png

This affects me when I have to take a value to perform an operation or make a graph.

Does anyone know what this problem is due to and how I could solve it?

Cisco DNA Center Add-on Cisco DNA Center App 

0 Karma

mlhadmin
Explorer

I don't like that this add-on is using INDEXED_EXTRACTIONS by default, with no seemingly easy way to switch from using them with the way that the scripted input works... Hopefully this will be improved now that Cisco owns Splunk...

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...