# Live threat map with elastic & Kibana

**URL:** <https://discuss.elastic.co/t/live-threat-map-with-elastic-kibana/98093>\
**Category:** Kibana\
**Created:** [August 23, 2017, 2:05pm UTC](https://discuss.elastic.co/t/live-threat-map-with-elastic-kibana/98093 "2017-08-23T14:05:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [August 23, 2017, 2:05pm UTC](https://discuss.elastic.co/t/live-threat-map-with-elastic-kibana/98093/1 "2017-08-23T14:05:47Z")

</div>

Hello Team,

Is it possible with Kibana & Elasticsearch t configure a live cyber threat map? I am sure you guys must have seen on the internet something like this where live threat map displays the Geo and IP addresses where this malicious activity coming from.

[https://community.blueliv.com/map/](https://community.blueliv.com/map/)  
[https://threatmap.bitdefender.com/](https://threatmap.bitdefender.com/)

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [August 23, 2017, 6:08pm UTC](https://discuss.elastic.co/t/live-threat-map-with-elastic-kibana/98093/2 "2017-08-23T18:08:09Z")

</div>

Yes, Kibana ships with region maps now, and you can can do GeoIP enrichment of your data as part of your ingest pipeline (via logstash, ingest node, or I think even beats). The data enrichment would map the IP address to location (a coordinate I believe) which I believe is mapped to a region as part of the aggregation.

Kibana would show basically a regional heatmap, not points like in the demo you linked to.

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [August 24, 2017, 4:16am UTC](https://discuss.elastic.co/t/live-threat-map-with-elastic-kibana/98093/3 "2017-08-24T04:16:27Z")

</div>

Hi there,

So would you please help me on this regards to configure the heat map using Geo? I mean I have multiple honeypots setup which can be used to plot that data? Like opencanary

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [August 25, 2017, 8:35pm UTC](https://discuss.elastic.co/t/live-threat-map-with-elastic-kibana/98093/4 "2017-08-25T20:35:30Z")

</div>

You should only need to index records in Elasticsearch with GeoIP information to get this to work.

A lot of people run the ingestion through Logstash and use the [GeoIP filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-geoip.html) to enrich their data from just the IP address. I thought you could use the ingest node too, but [the list of processors](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest-processors.html) doesn't include GeoIP, so I guess I was wrong.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2017, 8:35pm UTC](https://discuss.elastic.co/t/live-threat-map-with-elastic-kibana/98093/5 "2017-09-22T20:35:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
