
Build a Grafana Geomap of Traffic and Threat Score
A Grafana Geomap showing traffic by country and coloured by threat score takes about an hour to build. Almost none of that hour is the map.
Spots 

A Grafana Geomap showing traffic by country and coloured by threat score takes about an hour to build. Almost none of that hour is the map.

The map is a built-in panel and it does what you'd expect. The work is upstream: getting a country code and a risk score onto every log line, cheaply enough that you're not paying per request for the privilege. And if you search for this, you'll find a pile of tutorials that solve it with a panel that stopped loading in May 2025. Use the Geomap panel. The Worldmap plugin is AngularJS, and Angular support was removed outright in Grafana 12.
Enrich the log line at the edge with an Nginx module reading local MMDB files, or batch-enrich unique IPs through an API and cache the result. Both work. They fail at different scales. Ship with Alloy, not Promtail. Promtail was removed from Loki in 3.7.3. Colour the map by max threat score, size markers by request count. Don't average them.
The gotchas that will eat your afternoon: latitude and longitude come back as strings, Geomap only auto-detects a field literally named lookup, and X-Forwarded-For is spoofable. You'll end up with one panel that answers two questions at once: where is my traffic from, and how much of it should I be worried about. The second question is the one nobody's dashboard answers.
One Geomap panel. Countries shaded by the highest threat score seen from that country in the window, with a circle marker sized by request volume sitting on top. A country that's big and green is fine. A country that's small and red is the one you want to click into.
The pipeline is four pieces: Nginx writes a JSON access log that already contains the country and the risk score, Alloy tails it, Loki stores it, Grafana queries it. Nothing here is exotic. The only decision that matters is how the country and score get into that log line, which is the next section and the bulk of the article.
I'm using Nginx because it's what most people reading this have in front of them. Traefik, Caddy, or an ALB with structured logs all work the same way once the fields exist; only the enrichment step changes. Why the tutorial you found doesn't work Worth two minutes before you copy anything from elsewhere. Worldmap is gone, not deprecated
The Worldmap Panel plugin page says it's deprecated and points you at Geomap, now the only world map panel Grafana ships. The repo was archived on January 23, 2025. More importantly, Worldmap is an AngularJS plugin, and Angular support was removed entirely in Grafana 12. There's no config toggle to bring it back.
So this isn't a "you should migrate eventually" situation. On any supported Grafana, a Worldmap panel doesn't render. Dashboards on grafana.com still ship it, blog posts from December 2025 still teach it, and if you ask ChatGPT this question it'll tell you to install the plugin. I tried. It did.
The Loki 3.7 release notes put it plainly: Promtail was deprecated in Loki 3.0 and has been removed as of 3.7.3. The code lives in Alloy now.
A Grafana Geomap showing traffic by country and coloured by threat score takes about an hour to build.
