UDT - Rogue Devices

I have a approved Whitelist using DNS names, which shows to have 200 odd devices in the list.

When I look at the rogue devices, there are >300 listed and on closer inspection some of them are devices which are in my allowed list (some have multiple NIC's).

Why is the correlation not working correctly, I see a similar issue if I use IP addresses.