To enable DNS lookups to occur automatically on the web server logs, add the following code to the $SPLUNK_HOME/etc/apps/operational_intelligence/local/props.conf file. If there is no props.conf file, then you will need to create one:
[access_combined] LOOKUP-dns = dnsLookup clientip OUTPUTNEW clienthost