I am guessing that SourceIP is your field that contains an IP address. If this is true try:
sourcetype="TEST" SourceIP=* | stats count by SourceIP | geoip SourceIP
... View more
There were a bug in the app for distributed searches, fixed in 1.1.3
see http://apps.splunk.com/app/368/
Or install the app on all the search-peers.
... View more