i'm trying to figure out how/when/where Splunk resolves the RemoteHostName field in WinNetMon. I assume this is done using DNS or local hosts files, but is it done by the Forwarder, Indexer, or Search Head?