I have lookup table in splunk.
I want check if ever been update in Splunk using output lookup command
This solved question seems to be what you're looking for:
Solved: How to get the Audit for Lookup files modification... - Splunk Community
If you don't want any changes at all, and you're on a *nix system, can you deploy your lookup with read-only permissions on the file within the app?