Why is Germany using NTP servers from AT pool so intensiv

Dear All,
sorry for late response but I was on leave.
I manage these 3 server with my github account “github@ma.yer.at” The servers have the following IP addresses: 2001:628:21f0:80::80:29 , 2001:628:21f0:80::80:35 and 2001:628:21f0:80::80:160
The names are entp3.iiasa.ac.at , entp1.iiasa.ac.at and entp2.iiasa.ac.at

… I built a new tool recently that tracks how often a server IP is returned in DNS answers for each country.

And how does it work ? Can you check it for my servers ?

I could send you this endless long “mrulist” with IP addresses as /128 or if you want as unique /32 with counts for each entry.
Resolving names for this “mrulist” takes forever.

This graph, I sent in my initial posting, comes from NetFlow. The internet access router sends its flow data to a central ELK stack server. There I can filter for NTP service and beside lot of other information I get this GeoIP graph just for NTP.

// Hans