What Splunk server should contain the lookup tables for all servers to use?
If the SH is part of a cluster then, yes, put the lookup file on one of them and the SH will replicate it to others.
If the SHs are not clustered then you'll have to create the lookup on all of them.
Great, so do I create lookup tables only on one SH or all please?
If the SH is part of a cluster then, yes, put the lookup file on one of them and the SH will replicate it to others.
If the SHs are not clustered then you'll have to create the lookup on all of them.
Lookup files are stored on search heads. They're sent to indexers as part of the search bundle.