If you are using outdated maxmind db in your splunk version, you will see some of the location is not right for a few IPs. Follow these steps to update the maxmind GeoLite2-City db file:
- You can go to this site, http://dev.maxmind.com/geoip/geoip2/geolite2/
- Download GeoLite2-City.mmdb
- Replace it with $SPLUNK_HOME/share/GeoLite2-City.mmdb, usually at /opt/splunk/share in any Linux host
- Don’t need to restart splunk, run new query in splunk and the db will be refreshed itself.