I have seen this before when a rule creates an Incident or Infers an alert and the wrong field is being used as "DetectionIP" in the Rule Action. In one case, someone had "DetectionTime" in the "DetectionIP" field, so the LEM was adding a node a second until the license was consumed.
Alternatively, it could be that something is sending logs in a format we're not expecting (maybe a bad connector config?) and so part of the log event is getting normalized as the DetectionIP and added as a node. Any idea what the source is for the logs? Are the right connectors configured?