I'd like to know how often the native IP geo location database is updated in Splunk. Is the native database better than the maxmind database?
This isn't official, but I believe the database is updated with each release. Splunk uses MaxMind as the geoip datasource.
You are right and it seems pretty official ... good thing we will have the option to choose at a later stage ...
http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command