There has been a lookup dnslookup in splunk for a long time now.
name to ip:
| lookup dnslookup clienthost AS host OUTPUT clientip as ip
ip to name:
| lookup dnslookup clientip AS ip OUTPUT clienthost AS host
if you have lookup table that contains the ip and the host and the fields are: ip, host lets call it
dns.csv and you have a search that capture the host
you can run the following search using the
... your search to find host ... | lookup dns.csv host OUTPUTNEW ip ...
very nice explanation here:
hope it helps