Splunk Enterprise

Duplicate values in Cisco DNA logs

AlonsoHM
Loves-to-Learn Lots

Thank you in advance for your help community

I performed the integration of Cisco DNA to Splunk

  • Created my "cisco_dna" index on my Heavy Forwarder
  • I installed the Cisco DNA Center Add-on on my Heavy Forwarder (https://splunkbase.splunk.com/app/6668)
  • Added the account in the add-on (username, password, host)
  • Activated all the inputs:
    • cisco:dnac:clienthealth
    • cisco:dnac:devicehealth
    • cisco:dnac:compliance
    • cisco:dnac:issue
    • cisco:dnac:networkhealth
    • cisco:dnac:securityadvisory
  • I also created my “cisco_dna” index on my Splunk Cloud instance.
  • Installed the Cisco DNA Center App (https://splunkbase.splunk.com/app/6669)
  • Done, I started receiving logs in Splunk from Cisco DNA

But when validating the dashboards in the APP and reviewing the search results I noticed that the values of the fields are duplicated.

AlonsoHM_0-1733266402127.png

Even if I apply some dedup to any of the fields, the result is “only one duplicate value”.

AlonsoHM_1-1733266540326.pngAlonsoHM_2-1733266625761.png

This affects me when I have to take a value to perform an operation or make a graph.

Does anyone know what this problem is due to and how I could solve it?

Cisco DNA Center Add-on Cisco DNA Center App 

0 Karma

mlhadmin
Explorer

I don't like that this add-on is using INDEXED_EXTRACTIONS by default, with no seemingly easy way to switch from using them with the way that the scripted input works... Hopefully this will be improved now that Cisco owns Splunk...

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...