5.3 Elastic Maps & Geospatial Telemetry Analysis

Key Takeaways

  • Elastic Maps requires geographic coordinates to be mapped natively as Elasticsearch geo_point data types to leverage Lucene BKD-tree spatial indexing.

  • Ingest pipelines utilize the geoip processor and MaxMind GeoLite2 databases to translate source.ip and destination.ip into ECS-compliant geographic objects containing coordinates, country codes, and ASN details.

  • Elastic Maps multi-layer architecture combines Point-to-Point network flow vectors, choropleth geopolitical boundaries, and dynamic cluster/grid aggregations (geohash and H3 hexes) into composable security views.

  • Impossible travel analytics calculate the velocity between consecutive authentications for a single identity, alerting when geographic separation divided by elapsed time exceeds physical transit feasibility.

  • Interactive spatial filtering with drawn shapes, bounds and distance circles turns map selections into spatial filters (geo_shape-based queries) that isolate regional threat activity.

Last updated: September 2026

Adversaries operate across global network infrastructures, routing intrusions through multi-hop proxies, cloud hosting providers, bulletproof datacenters, and compromised residential endpoints. In security operations, network telemetry devoid of spatial context forces analysts to manually cross-reference IP addresses against external WHOIS and geolocation services, introducing unacceptable latency into incident triage.

Elastic Maps transforms raw network and authentication events into dynamic geospatial intelligence. By leveraging Elasticsearch's native spatial indexing structures and multi-layered mapping engine, SOC teams can track exfiltration flow paths, analyze distributed brute-force campaigns by country of origin, detect impossible travel credential anomalies, and apply interactive geographic boundaries to isolate regional threat activity.


Geospatial Foundations & The Ingest-Time GeoIP Enrichment Pipeline

Geospatial analysis in the Elastic Stack depends upon strict data modeling and automated ingest-time enrichment. Raw IP strings (such as 198.51.100.45) cannot be plotted on a map; they must first be translated into physical geographic coordinates and indexed using specialized spatial data structures.

The geo_point Mapping Type & Lucene BKD-Trees

In Elasticsearch, geographic locations are represented by the geo_point field data type. A geo_point field stores latitude and longitude coordinate pairs:

{
  "mappings": {
    "properties": {
      "source.geo.location": {
        "type": "geo_point"
      },
      "destination.geo.location": {
        "type": "geo_point"
      }
    }
  }
}

Unlike standard numeric fields, geo_point fields are indexed internally using multidimensional BKD-trees (block KD-trees). BKD-trees partition two-dimensional space into hierarchical bounding boxes, allowing Elasticsearch to execute spatial bounding box, polygon, and distance queries in sub-millisecond time across hundreds of millions of records.

The Ingest Pipeline geoip Processor

During log ingestion (via Elastic Agent integrations or Logstash), streaming documents pass through an Ingest Pipeline configured with one or more geoip processors. The processor inspects an IP field, queries an internal geolocation database, and writes structured metadata into Elastic Common Schema (ECS) fields:

{
  "geoip": {
    "field": "source.ip",
    "target_field": "source.geo",
    "properties": [
      "location",
      "country_iso_code",
      "country_name",
      "region_name",
      "city_name",
      "continent_name"
    ]
  }
}

In standard Elastic Stack deployments:

  • Automated Database Management: Elasticsearch's GeoIP downloader automatically fetches and updates the free MaxMind GeoLite2 City, Country, and ASN databases from Elastic's GeoIP endpoint. (The Elastic Maps Service supplies basemaps and boundary layers, not the GeoIP databases.)
  • ECS Geolocation Fields: The processor populates standardized fields:
    • source.geo.location: Coordinates formatted as {"lat": 40.7128, "lon": -74.0060}.
    • source.geo.country_iso_code: 2-letter ISO 3166-1 country code (e.g., US, DE, JP).
    • source.geo.country_name: Full country designation.
    • source.as.number & source.as.organization.name: Autonomous System details (e.g., 15169, Google LLC), usually added by a second geoip processor that uses the GeoLite2-ASN database. They are vital for telling residential ISPs apart from cloud hosting providers.

Custom Enterprise GeoIP Databases for Private Infrastructure

Standard MaxMind databases cannot resolve internal private IPv4 subnets (RFC 1918: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). If internal traffic is passed through the public GeoIP processor, the fields remain unpopulated.

To visualize lateral movement and internal traffic across corporate sites, security teams build custom .mmdb database files or deploy an Elasticsearch Enrich Processor (enrich policy). This maps internal subnets to physical enterprise campus, datacenter, and branch office coordinates, ensuring internal endpoints are fully mappable in Elastic Maps.


Elastic Maps Multi-Layer Architecture for SecOps

Elastic Maps employs a composable layer architecture where analysts stack multiple distinct visual representations on top of basemap cartography provided by the Elastic Maps Service (EMS). Each layer connects to an independent data source, applies unique query filters, and renders telemetry using specialized spatial techniques.

+---------------------------------------------------------------------------------------+
|                         ELASTIC MAPS MULTI-LAYER STACK                                |
+---------------------------------------------------------------------------------------+
| LAYER 4: Discrete Vector Alerts (Individual points for Critical C2 / Malware alerts)  |
|          [Target: .alerts-security.alerts-default | Marker: Red Skull | Zoom: 6 to 24]|
+---------------------------------------------------------------------------------------+
| LAYER 3: Point-to-Point Flow Lines (Connecting source.geo to destination.geo)         |
|          [Width scaled by sum(destination.bytes) | Outbound exfiltration channels]    |
+---------------------------------------------------------------------------------------+
| LAYER 2: Hexagonal Grid Cluster Aggregation (H3 / geohash clusters for firewall logs) |
|          [Cells colored by event volume | Dynamic zoom-dependent clustering]          |
+---------------------------------------------------------------------------------------+
| LAYER 1: Geopolitical Choropleth (Country boundary polygons shaded by threat score)   |
|          [Joined via source.geo.country_iso_code to EMS Vector Boundaries]            |
+---------------------------------------------------------------------------------------+
| BASEMAP: Dark Mode EMS Vector Cartography (Roads, coastlines, geopolitical borders)   |
+---------------------------------------------------------------------------------------+

1. Vector (Documents) Layers

The Vector Documents layer plots individual Elasticsearch documents as discrete markers on the map. This layer is ideal for low-volume, high-severity telemetry—such as detection alerts, privileged access events, or endpoints experiencing ransomware activity.

  • Analysts can customize marker symbols (shapes, icons) and scale marker radius by metrics such as event.risk_score.
  • Clicking a marker opens a popover displaying document details and provides direct pivots to Kibana Discover or Timeline investigations.

2. Cluster / Grid Aggregation Layers

Attempting to plot 10,000,000 firewall documents as individual points crashes the browser DOM and results in visual clutter. To visualize massive event volumes, Elastic Maps uses Grid Aggregations:

  • Geohash Grid (geohash_grid): Divides the globe into hierarchical rectangular bounding boxes identified by geohash strings.
  • H3 Hexagonal Grid (geo_hex_grid): Divides the map into a uniform hexagonal grid using Uber's H3 spatial indexing system. Hexagons eliminate the directional edge distortion of rectangular grids.
  • Dynamic Resolution: As the analyst zooms in, the grid dynamically re-aggregates at higher spatial resolutions, splitting large country-level hexagons into municipal-level clusters.

3. Point-to-Point (Network Flow) Lines

The Point-to-Point layer aggregates source and destination locations from your documents (for example source.geo.location and destination.geo.location) and draws lines between them.

  • Directional Curves: Renders geodesic curved lines depicting traffic trajectory from origin to destination.
  • Metric Scaling: The width of the line is dynamically scaled by network.bytes or network.packets, while line color reflects event.outcome or network.transport.
  • SecOps Application: Immediately reveals large data exfiltration channels crossing international boundaries, remote access pivoting, or internal endpoints communicating with C2 nodes in embargoed jurisdictions.

4. Choropleth (Geopolitical Boundary) Layers

A Choropleth layer shades geopolitical regions (countries, states, provinces) based on aggregated metrics:

  • EMS Vector Boundaries: Elastic Maps Service provides vector boundary polygons for nations and administrative subdivisions worldwide.
  • Join Mechanism: The layer executes a terms aggregation on an index field (such as source.geo.country_iso_code) and performs an in-memory client-side join against the ISO 3166-1 alpha-2 property of the EMS boundary layer.
  • SecOps Application: Highlighting global origins of credential stuffing campaigns or visualizing firewall drop volumes by nation state.

Detecting Impossible Travel & Impossible Velocity Anomalies

One of the most powerful identity threat detection workflows enabled by geospatial telemetry is the detection of Impossible Travel (also termed Impossible Velocity).

Threat Model

Adversaries who compromise corporate credentials (via phishing, session token theft, or credential stuffing) frequently authenticate from their own infrastructure or commercial VPN egress nodes while the legitimate user is actively working from their home office or corporate headquarters. This results in the same user identity generating successful authentication events from geographically disparate locations within a physically impossible time window.

+---------------------------------------------------------------------------------------+
|                        IMPOSSIBLE VELOCITY ANOMALY TIMELINE                           |
+---------------------------------------------------------------------------------------+
| Event 1: user.name = 'sarah.connor'                                                   |
| @timestamp: 2026-09-30T14:00:00Z                                                      |
| Location:   New York City, United States (source.geo.country_iso_code: 'US')          |
| Provider:   Residential ISP (AS7018 Verizon)                                          |
|                                                                                       |
| [ Elapsed Time: 25 Minutes (1,500 Seconds) | Physical Distance: ~10,850 km ]          |
|                                                                                       |
| Event 2: user.name = 'sarah.connor'                                                   |
| @timestamp: 2026-09-30T14:25:00Z                                                      |
| Location:   Tokyo, Japan (source.geo.country_iso_code: 'JP')                          |
| Provider:   Cloud Hosting Datacenter (AS13335 Cloudflare / DigitalOcean)              |
|                                                                                       |
| CALCULATION: Velocity = 10,850 km / 0.417 Hours = ~26,000 km/h (about Mach 21)          |
| EVALUATION:  PHYSICALLY IMPOSSIBLE -> HIGH-SEVERITY COMPROMISED CREDENTIAL ALERT      |
+---------------------------------------------------------------------------------------+

Mathematical Formulation

Elastic Security does not ship a single built-in impossible-travel calculator. Analysts, custom rules or external scripts estimate velocity by dividing the great-circle distance between two login locations by the time between them:

Velocity=Geodesic Distance(Location1,Location2)ΔTimestamp\text{Velocity} = \frac{\text{Geodesic Distance}(\text{Location}_1, \text{Location}_2)}{\Delta \text{Timestamp}}

A common rule of thumb treats speeds above roughly 1000 km/h1000\text{ km/h} (faster than a commercial flight) as suspicious.

Investigation & False Positive Elimination

Before escalating an impossible travel alert to incident containment, an analyst must rule out common enterprise false positives:

  1. Corporate VPNs & Cloud Access Security Brokers (CASB): Telemetry from Zscaler, Cloudflare Access, or corporate Palo Alto GlobalProtect gateways terminates at regional egress nodes. A user in London browsing an internal app routed through a US-East CASB gateway will appear to authenticate from New York.
  2. Mobile Roaming Carrier Gateways: Mobile devices connected via cellular roaming route data back to their home carrier's GGSN/PGW gateway. An employee traveling in Germany on a UK SIM card may register IP addresses belonging to British telecom carriers.
  3. Autonomous System (AS) Verification: Analysts check source.as.organization.name. If one authentication originates from a known residential ISP (e.g., Comcast, BT) and the concurrent login originates from a commercial hosting provider (e.g., OVH, DigitalOcean, Linode, AWS), the probability of compromised credentials or adversary proxy usage is exceptionally high.

Spatial Filtering & Threat Intel Geo-Overlays

Elastic Maps provides interactive spatial tools that directly translate visual selections into underlying Elasticsearch Query DSL filters, allowing analysts to isolate and investigate geographic activity seamlessly.

Interactive Spatial Drawing Tools

When exploring telemetry in Elastic Maps, analysts can draw geometries directly on the canvas:

  • Bounding Box (Rectangle): Clicking and dragging a rectangle across a geographic region. Kibana converts the drawing into a spatial filter that constrains all map layers and synced dashboard panels.
  • Polygon Tool (Lasso): Drawing a multi-point polygon around a specific conflict zone, disputed border, or high-risk maritime region. Converted into a spatial filter built on a geo_shape query.
  • Distance Radius (Circle): Selecting an asset location (e.g., a corporate headquarters) and specifying a radius (e.g., 50 km). Converted into a distance-based spatial filter, isolating all events occurring within that perimeter.

Incorporating External Threat Intel Geo-Feeds

Security teams can enrich Elastic Maps with external threat intelligence feeds:

  • STIX/TAXII & MISP Integration: Threat intelligence integrations index indicators of compromise (IOCs) tagged with infrastructure locations.
  • Sanctioned / Embargoed Geographies: By importing custom GeoJSON vector layers containing OFAC-sanctioned nation boundaries, SOC analysts can set up real-time visual alerts whenever corporate egress traffic touches sanctioned territories.
  • Bulletproof Hoster Overlays: Known bulletproof hosting providers and bulletproof autonomous systems can be plotted as reference vector layers, visually flagging when enterprise endpoints initiate connections to suspicious geographic hubs.
Loading diagram...
Geospatial Telemetry Ingestion, GeoIP Enrichment & Elastic Maps Multi-Layer Architecture
Test Your Knowledge

A SOC team deploys a new firewall integration and attempts to build an Elastic Map showing inbound connection origins. However, when attempting to add a Documents layer or Grid aggregation layer, Kibana reports that no geospatial fields are available in the Data View. What is the fundamental requirement to enable geospatial visualizations in Elastic Maps?

A

The latitude and longitude values must be stored as separate float fields named geo.lat and geo.lon

B

The index must be configured with a field named location mapped as a keyword data type

C

The coordinates must be parsed and mapped as an Elasticsearch geo_point data type, typically populated via an ingest pipeline geoip processor

D

Elastic Maps requires all coordinates to be pre-rendered into SVG vector tiles on the Kibana server

Test Your Knowledge

An analyst investigates an alert for 'Impossible Travel' triggered by a user's Okta login events. Within a 15-minute window, the user logged in from London, UK and subsequently from Frankfurt, Germany. Before confirming account compromise and disabling the account, what network and geospatial metadata should the analyst evaluate to rule out an enterprise false positive?

A

Check whether the index lifecycle management (ILM) policy rolled over the shard during the 15-minute window

B

Inspect the Autonomous System organization and ISP metadata (source.as.organization.name) to determine if the user connected through a corporate VPN gateway, cloud proxy, or trusted carrier network

C

Recalculate the date histogram interval to 1-second fixed buckets to see if the events happened concurrently

D

Reindex the authentication data stream into a cold storage tier to check the inverted index term frequency

Test Your Knowledge

A threat intelligence team wants to visualize high-volume outbound network traffic to detect potential command-and-control (C2) channels and data exfiltration. They want a map layer that explicitly depicts the direction and volume of traffic flowing between internal corporate endpoints and external threat indicators. Which Elastic Maps layer type directly supports this requirement?

A

Choropleth layer shaded by destination.bytes

B

Tile layer utilizing external OpenStreetMap raster imagery

C

Heatmap density layer calculated from destination.geo.location

D

Point-to-Point (network flow) vector layer connecting source.geo.location to destination.geo.location with line width scaled by network.bytes

Sections you finish are checked off in the contents.