Try this
(sourcetype=nessus:scan plugin_id=* severity=critical "host-ip"=*) OR (sourcetype=nessus:plugin id=*) | fields host-ip, host_end, solution, description <<including all relevant fields>> | stats values(*) as * by plugin_id
... View more
The other option would be to create a lookup (updated periodically) of nessus:plugin and use that to get solution & description
sourcetype=nessus:scan plugin_id=* severity=critical "host-ip"="A.B.C.D" | lookup nessusplugin.csv id AS plugin_id OUTPUT solution description | table host-ip, host_end, plugin_id, solution, description
http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Lookup
... View more