Looks like the admin team has upgraded to the latest version 188.8.131.52 and after the upgrade only i'm seeing this issue. The lookup file contains just 1000+ entries and when its used with the lookup command its failing miserably . Does it has to do with the physical memory.?
I can't believe that the splunk cant parse the results with lookup file having 1000 entries for even last 60 minutes
index=wineventlog src_user!="$" EventCode=4725 user!="$" sourcetype="WinEventLog:Security" [|inputlookup Disabled | fields user ] | stats count by user