How can agencies unify smart city data to improve public services?

Every day, cities generate millions of data points — from water pressure readings to traffic signal state changes to air quality alerts. Too often, that data stays across separated IT and OT environments, trapped in systems that were never designed to share it, which slows response and hides problems until they become outages.

What are OT and IT, and why does it matter for smart cities?

Operational technology (OT) is the hardware and software that monitors and controls physical infrastructure (pumps, valves, signals, building systems). 

Informational technology (IT)  is the hardware and software supporting  agencies in investigating incidents, coordinating response, and measuring performance (identity, endpoint security, network security, analytics platforms). 

When OT and IT data remain separated, agencies lose the context needed to act quickly and safely.

This article explains a practical way to bridge OT and IT data with Elastic, so you can move from isolated sensor readings to a unified operational view with searchable, governed, real-time operational insight.

Why is IT and OT data convergence changing how cities operate?

IT and OT convergence is the shift away from treating operational technology and information technology as separate domains with separate ownership and toward a model where data, tools, and processes flow between them as one system.

For decades, agencies ran OT and IT as parallel worlds with different teams, different budgets, and different vendors. That separation made sense when OT systems were closed and physically isolated. It makes far less sense today, when a traffic signal controller, a water treatment sensor, and a city laptop can all sit on the same network path. 

IT and OT data convergence becomes even more important as organizations adopt AI. The value AI delivers is greater when it has context from unified data and can support teams with a unified operational picture and a better understanding of what is happening across the systems that run the city.

How does Elastic solve protocol sprawl for smart city data?

Elastic reduces protocol sprawl by using a single ingestion architecture, the Elastic Agent managed by Fleet, to normalize data from legacy industrial protocols and modern IoT sources into Elastic Cloud.

Architecture componentWhat it doesWhy it matters for agencies
Sensors and devicesPhysical infrastructure: pumps, traffic lights, meters, HVAC, air monitorsSource of operational truth
Elastic Agent (edge)Runs on gateways/servers to collect logs/metrics and ship securelyReduces tool sprawl; consistent policy and upgrades
FleetCentral management for thousands of Elastic AgentsOne control plane for rollout, config, and compliance
Elastic CloudCentral datastore and search/analytics platformOne place to correlate OT and IT data
Kibana dashboardsVisualizations and workflows for operators and analystsFaster triage and clearer situational awareness

As a result, with Elastic, data from a decades-old valve controller can be indexed and explored with the same consistency as telemetry from a modern IoT sensor, so teams spend less time translating formats and more time resolving issues. 

It also improves interoperability by giving legacy and modern systems a common data layer, making it easier to connect systems across different protocols, vendors, and generations of infrastructure.

How do agencies navigate proprietary protocols and vendor lock-in challenges?

While many OT protocols are manufacturer-specific, the true challenge for municipalities is long-term interoperability, ensuring that data remains accessible regardless of which hardware vendor provided the sensor.

Standards like Modbus, PROFINET, and DNP3 typically operate within closed ecosystems. This siloed approach creates significant friction when agencies attempt to integrate new hardware, rotate vendors, or consolidate telemetry into a single operational view.

To counter this, the industry is shifting toward vendor-neutral frameworks. For instance, OPC UA provides a common interface for cross-manufacturer communication. Agencies should apply this same logic to their analytics platforms: adopting a vendor-agnostic, open architectural layer that resides above device-specific protocols to maintain flexibility.

In this environment, open standards, Elastic Agent, and Fleet serve as the interoperability plane. Whether data originates from an MQTT broker or a legacy gateway, it is normalized into a unified schema in Elastic Cloud. This ensures that swapping hardware providers doesn't force a total rebuild of your Kibana dashboards or ML jobs, providing a practical defense against vendor lock-in.

What is the measurable ROI of Elastic for municipal agencies?

Agencies can quantify impact through faster troubleshooting, fewer blind spots, and earlier detection of operational anomalies (like leaks), especially when OT and IT signals are searchable together. Although use cases may vary depending on organizational needs, these outcomes are already being realized by organizations using Elastic in different operational contexts.

Water utility monitoring (leak detection and faster response)

  • Challenge: Limited real-time visibility across distribution networks can delay leak detection and increase non-revenue water.
  • Value: With high-volume telemetry searchable in near real time using piped ES|QL queries, teams can identify anomalies sooner, prioritize field response, and validate remediation faster.
  • Read the full customer story.

Smart parking and city revenue platforms (performance issue resolution)

  • Challenge: High transaction volumes and variable demand can create intermittent performance problems that are hard to pinpoint.
  • Value: Unified observability lets teams correlate app/server behavior with infrastructure signals and user-impact metrics.
  • Read the full customer story.

What does a unified smart city operations view look like in Kibana?

A Kibana dashboard showing a city map with highlighted utility zones, time-series charts for water pressure and flow, and an alerts panel listing abnormal sensor readings.
Kibana dashboards unify OT telemetry (pressure/flow/valve state) with IT health signals so operators can triage incidents faster.
A Kibana dashboard with transit lines overlaid on a map, vehicle status metrics, delay indicators, and an event timeline correlating network alerts with service disruptions.
Real-time service health and incident response views help transit teams correlate delays with infrastructure and network events.
A Kibana dashboard displaying parking transaction volume, revenue totals, device availability gauges, and alert cards for payment terminal errors.
Revenue and enforcement teams can track transactions, device uptime, and anomalies in one shared view.

Why does geospatial data matter for Smart City operations?

Almost every smart city data point already has a location attached to it. Elasticsearch stores that location natively as geo_point or geo_shape data, and Kibana Maps turns it into a layer agencies can search, filter, and correlate in real time.

A water pressure reading, a traffic signal fault, and a security alert on a substation network all mean more when you know where they happened relative to each other. Treating location as a first-class field, not an afterthought bolted on in a separate GIS tool, is part of what makes an OT/IT unification strategy actually usable day to day.

Geospatial use case examples for smart cities

  • Asset and vehicle tracking: Follow a transit vehicle, maintenance truck, or drone inspection route over time.
  • Density and hotspot analysis: Identify clusters such as leak reports or a parking demand hotspot.
  • Location-aware search: Combine location with other data to find events within a specific area and timeframe.
  • Security correlation: Enrich network events with location, which lets analysts see whether unusual OT network activity is coming from a location that makes sense for that facility.
Geospatial correlation view
Layering OT sensor locations, utility service boundaries, and security events on one map helps operators see the physical scope of an issue, not just a list of alerts.

How do you secure OT in smart cities?

While strict air-gapping remains a requirement for highly sensitive federal and defense infrastructure, many municipal agencies are intentionally connecting everyday operational systems to power modern smart city services. However, when OT becomes reachable from IT networks, the attack surface expands, and the blast radius can move beyond data loss into physical service disruption.

This is why guidance from organizations such as CISA and NIST emphasizes securing OT environments while accounting for their unique operational and safety requirements.

Whether you maintain strictly isolated environments or are embracing IT/OT convergence, Elastic Security supports an OT-aware approach. You can secure connected city infrastructure by applying Zero Trust, correlating IT and OT events to detect lateral movement, and using protocol-aware detections mapped to MITRE ATT&CK® for ICS.

Stop lateral movement from IT to OT

Attackers often start in IT (phishing, stolen credentials) and pivot toward OT. When OT and IT telemetry land in one platform, analysts can:

  • Investigate a phishing-driven endpoint event

  • Track identity and authentication activity

  • Correlate network behaviors and OT-side command anomalies

  • Build a single timeline that reduces handoffs between tools

  • Use AI-driven capabilities to automatically summarize complex IT/OT attack chains

Use protocol-aware detection

Instead of treating OT traffic as opaque, agencies can enrich and analyze it:

  • Decode and analyze industrial protocols (e.g., Modbus, DNP3, and CIP) to identify suspicious commands

  • Alert on behavior that’s unusual for a device, time, or segment (e.g., administrative writes at abnormal hours)

  • Reduce false positives by pairing network detections with asset and identity context

Map detections to MITRE ATT&CK for ICS

Mapping detections to MITRE ATT&CK for ICS helps teams:

  • Align detection coverage to known tactics and techniques

  • Communicate risk in a common language across leadership and technical teams

  • Prioritize gaps based on real adversary behaviors

As smart cities bring more OT, IT, and IoT data together, Elastic can help agencies build a more connected operational view, detect anomalies, strengthen security across their infrastructure, and reduce tool sprawl. You can start by setting up the MQTT integration to bring OT data into Elastic, use machine learning for anomaly detection to identify unusual patterns in city sensor data, and explore Elastic Security to help protect industrial and OT environments.

The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.