In most of my host fields today I have something like host=192.168.1.254. I would like Splunk to automatically query DNS and switch that IP to the hostname in DNS. Instead of "host=192.168.1.254" it would read "host=First-Floor-FileServer". I know there is a way to manually transform them, but if there was an automated way to do it, that would be preferable.
Have you had a look at my app (apologies for the shameless self promotion):
http://splunk-base.splunk.com/apps/88316/dnslookup
It doesn't quite do what you're asking but it is close.