It smells a lot like a AWS (Amazon Web Services) provisioned Enterprise Splunk server. It's probably their direction for centralized log aggregation. I don't know enough about the splunk daemon to know if spammy DNS queries is a sign of a problem, or if it's just the way it is - could go either way.