hi, Did you find a solution? We also update some lookup files periodically almost the same way and the file itself (/appl/splunk/etc/apps/APPNAME/lookups) will not update. The KV store is up to date, but the file not... If i delete the file in the APP before the update, then the file is new created. Did you insert in your script that you delete the file in the folder bevor update or is there an other solution? Greetings,
... View more