I have bunch of IPs and I would like to do reverse DNS and get the host names. So, can I include IPs in the search itself and get reverse DNS host names?
Answered in https://answers.splunk.com/answers/717313/how-do-i-do-a-reverse-dns-lookup-in-splunk-1.html
If you have a .csv of host name to ip mapping, you should be able to do a lookup. http://docs.splunk.com/Documentation/Splunk/6.3.1/SearchReference/Lookup