<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Sysmon - Could not load lookup=LOOKUP-eventcode in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690645#M114900</link>
    <description>&lt;P&gt;&lt;SPAN&gt;If you look under lookups,&amp;nbsp; it should show that those are all set and defined. So double check lookup up tables files / Lookup definitions / Automatic Lookups and check sysmon app context. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Also check if there's another lookup with that name, sometimes I have seen another same name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;#this should point to most of the sysmon TA code (transforms) or show another.&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk cmd btool transforms list eventcode --debug&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jun 2024 16:33:10 GMT</pubDate>
    <dc:creator>deepakc</dc:creator>
    <dc:date>2024-06-13T16:33:10Z</dc:date>
    <item>
      <title>Splunk Add-on for Sysmon - Could not load lookup=LOOKUP-eventcode</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690463#M114885</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Following the official instructions&amp;nbsp;&lt;A href="https://apps.splunk.com/apps/id/Splunk_TA_microsoft_sysmon" target="_self"&gt;https://apps.splunk.com/apps/id/Splunk_TA_microsoft_sysmon ,&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk Add-on for Sysmon 4.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I just deployed the addon for sysmon in my indexer, search head and deployment servers so I started to collect sysmon logs.&lt;/P&gt;&lt;P&gt;I am running Sysmon 15.14 on the endpoints. The logs started to flow into splunk but when I do searches on the index I constantly receive the following error:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;[indexer.mydomain.es, mysearchhead.mydomain.es] Could not load lookup=LOOKUP-eventcode&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I read the information in the&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/MSSysmon/Lookups" target="_self"&gt;https://docs.splunk.com/Documentation/AddOns/released/MSSysmon/Lookups&lt;/A&gt;&amp;nbsp;but I couldnt find the root cause. The csv are in the path indicated in the documentation. &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="corti77_0-1718196239014.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31291i4DE40DB0E0D65E75/image-size/medium?v=v2&amp;amp;px=400" role="button" title="corti77_0-1718196239014.png" alt="corti77_0-1718196239014.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any suggestion?&lt;/P&gt;&lt;P&gt;many thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 12:56:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690463#M114885</guid>
      <dc:creator>corti77</dc:creator>
      <dc:date>2024-06-12T12:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Sysmon - Could not load lookup=LOOKUP-eventcode</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690645#M114900</link>
      <description>&lt;P&gt;&lt;SPAN&gt;If you look under lookups,&amp;nbsp; it should show that those are all set and defined. So double check lookup up tables files / Lookup definitions / Automatic Lookups and check sysmon app context. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Also check if there's another lookup with that name, sometimes I have seen another same name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;#this should point to most of the sysmon TA code (transforms) or show another.&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk cmd btool transforms list eventcode --debug&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 16:33:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690645#M114900</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-06-13T16:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Sysmon - Could not load lookup=LOOKUP-eventcode</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690872#M114932</link>
      <description>&lt;P&gt;You were so right &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/79189"&gt;@deepakc&lt;/a&gt;&amp;nbsp;! Thanks a lot.&lt;/P&gt;&lt;P&gt;I had duplicate eventcode lookups created by&amp;nbsp;&lt;SPAN&gt;Microsoft Windows Defender Add-on for Splunk&amp;nbsp; and&amp;nbsp;Splunk_TA_microsoft_sysmon&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="corti77_0-1718612789912.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31356iFF832357F66B5DDE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="corti77_0-1718612789912.png" alt="corti77_0-1718612789912.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just removed Defender Add-on which is not officially supported. I need to find some other with support that I guess will not generate this type of conflict. Do you have any suggestion for this ? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 08:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690872#M114932</guid>
      <dc:creator>corti77</dc:creator>
      <dc:date>2024-06-17T08:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Sysmon - Could not load lookup=LOOKUP-eventcode</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690884#M114934</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I guess you can have same auto lookup attribute names inside the &lt;STRONG&gt;same App&lt;/STRONG&gt;, that then point to look up files being used.&amp;nbsp; but causes issues when same inside of another app (I know Splunk for saved searches sends a message with same name or duplicate, but I don’t think it does for lookups) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, something like this alert may help&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest splunk_server=local servicesNS/admin/search/data/props/lookups
| search attribute=LOOKUP-*
| stats count by attribute
```Filter or add ones that are OK as they may be other attributes that use similar lookups in the same App context```
```| search NOT attribute="LOOKUP-my_ok_lookup1" NOT attribute="LOOKUP- my_ok_lookup2"```
| eval duplicate=if(count &amp;gt; 1, "Yes", "No")
| where count &amp;gt; 1&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can then find out, explore if there are &lt;STRONG&gt;other&lt;/STRONG&gt; apps that use the same name attribute: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Example in your case eventcode&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest splunk_server=local servicesNS/admin/search/data/props/lookups
| search attribute=LOOKUP-eventcode&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have play and see if this helps. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 11:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690884#M114934</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-06-17T11:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Sysmon - Could not load lookup=LOOKUP-eventcode</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690885#M114935</link>
      <description>&lt;P&gt;No worries, glad it worked out out &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 11:39:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Sysmon-Could-not-load-lookup-LOOKUP-eventcode/m-p/690885#M114935</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-06-17T11:39:00Z</dc:date>
    </item>
  </channel>
</rss>

