How can agencies unify smart city data to improve public services?

Every day, cities generate millions of data points — from water pressure readings to traffic signal state changes to air quality alerts. Too often, that data stays across separated IT and OT environments, trapped in systems that were never designed to share it, which slows response and hides problems until they become outages.
What are OT and IT, and why does it matter for smart cities?
Operational technology (OT) is the hardware and software that monitors and controls physical infrastructure (pumps, valves, signals, building systems).
Informational technology (IT) is the hardware and software supporting agencies in investigating incidents, coordinating response, and measuring performance (identity, endpoint security, network security, analytics platforms).
When OT and IT data remain separated, agencies lose the context needed to act quickly and safely.
This article explains a practical way to bridge OT and IT data with Elastic, so you can move from isolated sensor readings to a unified operational view with searchable, governed, real-time operational insight.
Why is IT and OT data convergence changing how cities operate?
IT and OT convergence is the shift away from treating operational technology and information technology as separate domains with separate ownership and toward a model where data, tools, and processes flow between them as one system.
For decades, agencies ran OT and IT as parallel worlds with different teams, different budgets, and different vendors. That separation made sense when OT systems were closed and physically isolated. It makes far less sense today, when a traffic signal controller, a water treatment sensor, and a city laptop can all sit on the same network path.
IT and OT data convergence becomes even more important as organizations adopt AI. The value AI delivers is greater when it has context from unified data and can support teams with a unified operational picture and a better understanding of what is happening across the systems that run the city.
How does Elastic solve protocol sprawl for smart city data?
Elastic reduces protocol sprawl by using a single ingestion architecture, the Elastic Agent managed by Fleet, to normalize data from legacy industrial protocols and modern IoT sources into Elastic Cloud.
| Architecture component | What it does | Why it matters for agencies |
| Sensors and devices | Physical infrastructure: pumps, traffic lights, meters, HVAC, air monitors | Source of operational truth |
| Elastic Agent (edge) | Runs on gateways/servers to collect logs/metrics and ship securely | Reduces tool sprawl; consistent policy and upgrades |
| Fleet | Central management for thousands of Elastic Agents | One control plane for rollout, config, and compliance |
| Elastic Cloud | Central datastore and search/analytics platform | One place to correlate OT and IT data |
| Kibana dashboards | Visualizations and workflows for operators and analysts | Faster triage and clearer situational awareness |
As a result, with Elastic, data from a decades-old valve controller can be indexed and explored with the same consistency as telemetry from a modern IoT sensor, so teams spend less time translating formats and more time resolving issues.
It also improves interoperability by giving legacy and modern systems a common data layer, making it easier to connect systems across different protocols, vendors, and generations of infrastructure.
What is the measurable ROI of Elastic for municipal agencies?
Agencies can quantify impact through faster troubleshooting, fewer blind spots, and earlier detection of operational anomalies (like leaks), especially when OT and IT signals are searchable together. Although use cases may vary depending on organizational needs, these outcomes are already being realized by organizations using Elastic in different operational contexts.
Water utility monitoring (leak detection and faster response)
- Challenge: Limited real-time visibility across distribution networks can delay leak detection and increase non-revenue water.
- Value: With high-volume telemetry searchable in near real time using piped ES|QL queries, teams can identify anomalies sooner, prioritize field response, and validate remediation faster.
- Read the full customer story.
Smart parking and city revenue platforms (performance issue resolution)
- Challenge: High transaction volumes and variable demand can create intermittent performance problems that are hard to pinpoint.
- Value: Unified observability lets teams correlate app/server behavior with infrastructure signals and user-impact metrics.
- Read the full customer story.
What does a unified smart city operations view look like in Kibana?



Why does geospatial data matter for Smart City operations?
Almost every smart city data point already has a location attached to it. Elasticsearch stores that location natively as geo_point or geo_shape data, and Kibana Maps turns it into a layer agencies can search, filter, and correlate in real time.
A water pressure reading, a traffic signal fault, and a security alert on a substation network all mean more when you know where they happened relative to each other. Treating location as a first-class field, not an afterthought bolted on in a separate GIS tool, is part of what makes an OT/IT unification strategy actually usable day to day.
Geospatial use case examples for smart cities
- Asset and vehicle tracking: Follow a transit vehicle, maintenance truck, or drone inspection route over time.
- Density and hotspot analysis: Identify clusters such as leak reports or a parking demand hotspot.
- Location-aware search: Combine location with other data to find events within a specific area and timeframe.
- Security correlation: Enrich network events with location, which lets analysts see whether unusual OT network activity is coming from a location that makes sense for that facility.

How do you secure OT in smart cities?
While strict air-gapping remains a requirement for highly sensitive federal and defense infrastructure, many municipal agencies are intentionally connecting everyday operational systems to power modern smart city services. However, when OT becomes reachable from IT networks, the attack surface expands, and the blast radius can move beyond data loss into physical service disruption.
This is why guidance from organizations such as CISA and NIST emphasizes securing OT environments while accounting for their unique operational and safety requirements.
Whether you maintain strictly isolated environments or are embracing IT/OT convergence, Elastic Security supports an OT-aware approach. You can secure connected city infrastructure by applying Zero Trust, correlating IT and OT events to detect lateral movement, and using protocol-aware detections mapped to MITRE ATT&CK® for ICS.
Stop lateral movement from IT to OT
Attackers often start in IT (phishing, stolen credentials) and pivot toward OT. When OT and IT telemetry land in one platform, analysts can:
Investigate a phishing-driven endpoint event
Track identity and authentication activity
Correlate network behaviors and OT-side command anomalies
Build a single timeline that reduces handoffs between tools
Use AI-driven capabilities to automatically summarize complex IT/OT attack chains
Use protocol-aware detection
Instead of treating OT traffic as opaque, agencies can enrich and analyze it:
Decode and analyze industrial protocols (e.g., Modbus, DNP3, and CIP) to identify suspicious commands
Alert on behavior that’s unusual for a device, time, or segment (e.g., administrative writes at abnormal hours)
Reduce false positives by pairing network detections with asset and identity context
Map detections to MITRE ATT&CK for ICS
Mapping detections to MITRE ATT&CK for ICS helps teams:
Align detection coverage to known tactics and techniques
Communicate risk in a common language across leadership and technical teams
Prioritize gaps based on real adversary behaviors
As smart cities bring more OT, IT, and IoT data together, Elastic can help agencies build a more connected operational view, detect anomalies, strengthen security across their infrastructure, and reduce tool sprawl. You can start by setting up the MQTT integration to bring OT data into Elastic, use machine learning for anomaly detection to identify unusual patterns in city sensor data, and explore Elastic Security to help protect industrial and OT environments.
The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.