Known issues
Review known issues that can affect generated add-ons before you deploy Auto-schema output.
Generated add-ons can overlap with supported add-ons
Auto-schema can generate an add-on even when your sample events match a data source that already has a Splunk-supported add-on, such as Palo Alto Networks. When Auto-schema detects an existing Splunk-supported add-on (TA) for the corresponding data sample uploaded in the workflow, using the existing supported add-on is the recommended approach and is encouraged whenever it meets your onboarding requirements.
If you install both the generated add-on and the existing supported add-on in the same Splunk Cloud Platform environment, the add-ons can overlap and standard Splunk app and add-on precedence behavior applies. This can affect source type handling, search-time field extractions, event types, tags, and CIM normalization.
Before you deploy a generated add-on, check whether a supported add-on already covers the data source. Use the supported add-on when it meets your onboarding goal. If you deploy a generated add-on with an existing supported add-on, test the generated add-on in a non-production environment, review possible configuration conflicts, and retest after you upgrade either add-on.