All Apps and Add-ons

Sysmon Add-on - lookup eventcode not processed correctly

corti77
Contributor

hi,

I have splunk 9.0.6 and sysmon add-on 3.1.0. 

The lookup table called "microsoft_sysmon_eventcode.csv" correctly appears in Splunk Lookup Table Files list.

corti77_0-1700482421026.png

 

But, in the automatic lookup, the Lookup-eventcode is wrongly assigned to "eventcode" lookup instead of "sysmon_eventcode".

corti77_1-1700482459755.png

 

Searching for this "eventcode" lookup, it belongs to the app Defender.

corti77_2-1700482545604.png

 

Surprisingly, when I tried to fix this bug using the UI, the sysmon_eventcode lookup table did not appear in the dropdown list. I only see "sysmon-record_type-lookup".

corti77_0-1700482896017.png

 

Do you have any idea what might be happening?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...