Edit: This is NOT an answer, it is a work around.
I have since been able to get the data I needed, but only on our instance of Splunk ES...and only on active searches, not scheduled. I think there may be a setting in the background that I am not aware of.
The code that works is :
| tstats count by host
| lookup dnslookup clienthost as host OUTPUT clientip as Source_IP
| lookup dnslookup clientip as Source_IP OUTPUT clienthost as SourceName
|lookup ipam_report.csv network AS Source_IP OUTPUT network, location, owner, sitecode, vlan
| stats
values(host) as host
values(SourceName) as SourceName
sum(count) as Counted
values(network) as network
values(location) as location
values(owner) as owner
values(sitecode) as sitecode
values(vlan) as vlan
by Source_IP
|sort - Counted
| table host, Source_IP, network, vlan, SourceName, sitecode, location, owner, Counted
... View more