You may need to custom-extract the value (until you can get the sourcetype’s props.conf and transforms.conf updated).
Something like this should work:
<search>
| rex field=_raw "device=(<device>\S+)"
<rest of search>
from User warren – Stack Overflow https://stackoverflow.com/questions/75235524/splunk-query-to-get-comma-separated-value-as-single-value/75248139#75248139
via IFTTT