I ran for a while with
packetbeat -> logstash -> elasticsearch in elastic cloud
and the data is showing up in the SIEM App
I did notice the map on the Packetbeat dashboard is looking at the map in detail it is looking for client.geo.location
Data source Clusters and grids
Index pattern packetbeat-*
Geospatial field client.geo.location
client.ip
which my packetbeat on my mac does not fill but I just when to the map and added destination.geo.location
the showed up on the map.