Find large CSV lookups above 400 mb (500 mb limit) :
| rest splunk_server=* /servicesNS/-/-/data/transforms/lookups getsize=true f=size f=title f=type f=filename f=eai*|fields splunk_server filename title type size eai:appName
|where isnotnull(size)|eval KB = round(size / 1024, 2)|fields - size
| sort - KB
| search KB>400000
Use this to reduce CSV lookup (example) :
| inputlookup file.csv
| eval time_epoch = strftime(_time,"%s")
| where time_epoch>relative_time(now(),"-100d@d")
| outputlookup file.csv append=false