Is there a way on search query to resolve any IP result into hostname?
No app needed, Splunk comes with a DNS lookup out of the box:
some search returning a field called ip | lookup dnslookup clientip as ip OUTPUT clienthost as your_shiny_host_field
You need the dnslookup app:
Hi Im getting an "Unknown search command 'dnslookup'
Did you install the app on your Search Head? That is all I did and it worked great. It isn't my app so I would read through the app documentation and make sure that you have all prerequisites and see if there are any notes that will help you.