hi,
I have splunk 9.0.6 and sysmon add-on 3.1.0.
The lookup table called "microsoft_sysmon_eventcode.csv" correctly appears in Splunk Lookup Table Files list.
But, in the automatic lookup, the Lookup-eventcode is wrongly assigned to "eventcode" lookup instead of "sysmon_eventcode".
Searching for this "eventcode" lookup, it belongs to the app Defender.
Surprisingly, when I tried to fix this bug using the UI, the sysmon_eventcode lookup table did not appear in the dropdown list. I only see "sysmon-record_type-lookup".
Do you have any idea what might be happening?