The Traffic Origin tab in Total View is the investigation workspace for upstream origin data. Use it after the Highlights widget has flagged an indicator, or whenever you need the full detection history instead of a country summary.
Before you start
Your organization must have Traffic Origin permissions enabled. If the tab is missing, the feature is not on for your tenant.
GeoIP permissions are required to zoom the map beyond level 10.
Search supports a domain, IPv4/IPv6 address, ASN, or URL.
Open the tab
On the landing page, enter a domain, IPv4/IPv6 address, ASN, or URL.
Press Enter or click Total View.
Click the Traffic Origin tab.
What a detection is
Each point on the map and each row in the table is a detection event: an observation that traffic associated with the searched indicator was seen at a geographic location. It is not vehicle or road-traffic data. Color, clustering, and row counts describe how often and where those IP detections occurred.
Use the map view
The interactive map uses Google Vector Tiles. The default layer is dark mode. You can switch to satellite view.
Select a time period to filter detections. The map and table update together.
Review markers for IP detections. Markers cluster by proximity. Clusters show counts and change size as you zoom.
Click a cluster to zoom in and split it into smaller groups or individual points.
Use color grading to read density: hotter colors indicate higher detection counts.
Work from wide to narrow. Start with country or metro clusters, then zoom into a city or neighborhood when GeoIP permissions allow it. That is how a Highlights country list becomes a specific set of coordinates.
Use the table view
The table lists the same detections shown on the map. Columns include:
First seen timestamp
Last seen timestamp
IPv4/IPv6
Latitude and longitude
Country
User agent
Changing the time range updates the table and the map in real time. Select one or more row checkboxes to highlight the corresponding points on the map.
Use the table when pins overlap, when you need exact timestamps, or when you want to confirm that a hot cluster is many events rather than one noisy point.
Recommended investigation loop
Read the Highlights country list for a first-pass origin mismatch.
Open the Traffic Origin tab and set the time range.
Scan the map for dense clusters and unexpected countries.
Open the table, sort or scan first/last seen, country, and user agent.
Select rows to highlight those detections on the map.
Zoom permitted clusters to inspect local geography.
Correlate what you see with other Total View tabs (Threat Feeds, Infrastructure Variance, and related context).
Permissions and limits
No Traffic Origin tab: the feature is not enabled for your organization.
Map stops at zoom level 10: GeoIP permissions are missing.
Empty map or table: the indicator has no Traffic Origin detections in the selected time range. Widen the range or try another indicator.