I faced the same issue. As far as I understood exceeding of default volume of lookup table doesn't impact on the data itself as it just starts to be indexed. So it's enough just to hide this message from a dashboard. To do so add the level field to your Message module:
< module name="Message" layoutPanel="messaging" >
...
< param name="level">error< /param >
< /module >
And it will only emit messages equal to or higher than the specified level.
Splunk's internal logging levels are DEBUG INFO WARN ERROR FATAL (from most to least verbose).
... View more