Is there a way to add the src_ip Field to windows events?
Looking for options that do not involve a lookup.
You mean you want to collect and add it to the log events at the time of capture? If so, then short of writing your own input (or modifying the Splunk one) on the forwarder, I can not think of one.
Have you ever seen anybody setting the host=ip on inputs.conf? I wonder if the events themselves always have the hostname or computer name value in them and we can add the IP address via inputs.conf.