@AndySplunks The following search will show you the lookup files within Splunk and the last updated date. | rest splunk_server=local /servicesNS/-/-/data/lookup-table-files | table title updated This search is for when they are actually edited: index=_internal "Lookup edited successfully" |table _time namespace lookup_file user
... View more