Enrich events with geoIP information | Packetbeat

GEOIP_CHECK_CACHE - Check for updated database. If database has been updated, reload file handle and/or memory cache. GEOIP_INDEX_CACHE - Cache only the the most frequently accessed index portion of the database, resulting in faster lookups than GEOIP_STANDARD, but less memory usage than GEOIP_MEMORY_CACHE.

You can use Packetbeat along with the GeoIP Processor in Elasticsearch to export geographic location information based on IP addresses. Then you can use this information to visualize the location of IP addresses on a map in Kibana. The geoip processor adds information about the geographical location of IP addresses, based on data from the Maxmind GeoLite2 City Database.

