My apologies - I meant to close out this thread before it got posted, but it was hung up in moderation.
It's not a Splunk issue. Running lookup dnslookup on the IP reported the DNS name "datacenter.fiberdc.com.tr", but doing an nslookup on the DNS name comes back with a different IP (the one you noted above). So Splunk was behaving properly.
The IP in my logs does resolve to "datacenter.fiberdc.com.tr", but also correctly iplocates to Germany, as confirmed by multiple geolocation services.
Sorry to waste your time!
... View more