Known issues in the Splunk App for Content Packs

This version of the app has the following reported known issues. If no issues appear below, no issues have yet been reported.

Date filed Issue number Description Workaround
2026-02-02 ITSI-43340

[Content Pack for Cisco Enterprise Networks] The 3.0.0 release of the Cisco Catalyst Add-on for Splunk renamed cisco_dnac_host to cisco_catalyst_host, breaking content pack searches that use the old field name.

ITSI-42768 resolved this issue on January 28, 2026 for new Catalyst Center alerts integration connections. Existing alerts integration connections still have broken searches and require a manual fix.

  1. From the ITSI main menu, select Configuration > Data Integrations.
  2. The Integrations library tab is selected by default. Under Alerts, select Cisco Catalyst Center.
  3. In the row for your connection, select the actions () menu. Select Edit.
  4. Change the ITSI Drilldown Website URL field to the following and save your changes:
    1. Field: cisco_catalyst_host
    2. /dna/assurance/device/details?id=
    3. Field:DeviceID.
2026-01-27 ITSI-43302

[Content Pack for Cisco Data Center] The Cisco Nexus Dashboard service import module doesn't support case sensitive service names.

If you import two services with the same name that are differentiated only by uppercase or lowercase characters, the module shows that the import succeeded. However, the sandbox editor shows that only one of the services was imported.

Ensure that your services have unique and case insensitive names before you use the service import module.