hi,
I have splunk 9.0.6 and sysmon add-on 3.1.0.
The lookup table called "microsoft_sysmon_eventcode.csv" correctly appears in Splunk Lookup Table Files list.
corti77_0-1700482421026.png
But, in the automatic lookup, the Lookup-eventcode is wrongly assigned to "eventcode" lookup instead of "sysmon_eventcode".
corti77_1-1700482459755.png
Searching for this "eventcode" lookup, it belongs to the app Defender.
corti77_2-1700482545604.png
Surprisingly, when I tried to fix this bug using the UI, the sysmon_eventcode lookup table did not appear in the dropdown list. I only see "sysmon-record_type-lookup".
corti77_0-1700482896017.png
Do you have any idea what might be happening?