Hi @spl10, the easiest way to have a copy of lookups having low grants, it's scheduling an alert for each lookup attaching the result to the email. In this way you have all the csv files on your email and you haven't problems to search csv files that, only for your information, are in $SPLUNK_HOME/var/run/splunk/csv. If you don't want many emails, you could use the search from @ITWhisperer to aggregate all lookups in one csv file and send it by alert to your email. One additional information: when you make backup of your apps, you also make the backup of your lookups. Ciao. Giuseppe
... View more