Hi tksre,
If you have a lookup table in CSV format you are able to add it to Splunk and use the lookup
command to match users and output their IP address.
Your lookup-table should look like the following. (example)
user, ip
marc, 19.14.25.120
fred, 128.21.15.199
bob, 120.249.2.14
Use this documentation to upload and add that lookup table to splunk:
https://docs.splunk.com/Documentation/Splunk/7.0.2/Knowledge/ConfigureCSVlookups
You can then use the lookup
command to get the required data.
Example-Statement: index=example username=* | lookup nameofmylookuptable user AS username OUTPUT ip
The example assumes that the user in your eventdata is stored in a field called "username"
Further documentation:
https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Lookup