1) Create the list of verified hostnames as a CSV file. It is easy if the column containing the hostname values is the same name as Splunk's hostname. (i.e. if Splunk calls it "host=bob" your header should be "host" without the quotes.)
2) Open Splunk.
3) Navigate to Manager --> Lookups --> Add New --> Lookup Table File
4) Upload your file and name it hostname_lookup.csv (or whatever you want, have the filename end in .csv)
5) Under Manager --> Lookups --> Add New --> Lookup Definition