You can use a subsearch to add the results of the ldapsearch to your initial search query:
eventtype=msad-failed-user-logons (host="*") [| ldapsearch domain=xxxxxxx.xxx search="(&(objectclass=group)(cn=Administrators))"|ldapgroup|table member_name, member_domain] |fields _time,signature,src_ip,src_host,src_nt_host,src_nt_domain,user,Logon_Type, Logon_Account, Source_Workstation | ip-to-host |stats count by user,src_nt_domain |where count>=5 |sort -count |rename user as "Username", src_nt_domain as "Domain"
Use the search inspector to see how this adds the data from the ldapsearch to the base search.
... View more