See the answer by @niketnilay on this one, which includes the full code for a similar solution.
https://answers.splunk.com/answers/623803/trellis-display-of-two-values.html
However, I believe you may need to swap the order of your fields. That is, the "by" field may need to be by host if you want the trellis to break the results by host. Try it the way you have it and see if it works. If not, then swap it and see if that works.
... View more