Thank you in advance for your help community
I performed the integration of Cisco DNA to Splunk
But when validating the dashboards in the APP and reviewing the search results I noticed that the values of the fields are duplicated.
Even if I apply some dedup to any of the fields, the result is “only one duplicate value”.
This affects me when I have to take a value to perform an operation or make a graph.
Does anyone know what this problem is due to and how I could solve it?
I don't like that this add-on is using INDEXED_EXTRACTIONS by default, with no seemingly easy way to switch from using them with the way that the scripted input works... Hopefully this will be improved now that Cisco owns Splunk...
This is probably an INDEXED_EXTRACTIONS issue, see these, which should help