Hello all.
I am trying to complete something that should be easy. I wish to have IPs resolve to host names in the Splunk command. 
I have read the posts and the Splunk help on this, but nothing appears to be working properly with this. Accordingly,
Can anyone provide a valid and exact step-by-step for this, and do not point to the docs?
 
					
				
		
Like this:
... | lookup dnslookup clientip as host | table host,clienthost
 
					
				
		
Do you mean:
... | lookup dnslookup clientip as host | table host,clientip
 
					
				
		
No, because the lookup creates the field clienthost and furthermore, clientip does not exist (except inside of the lookup table).
