# Brute Force Watcher and Alert

**URL:** <https://discuss.elastic.co/t/brute-force-watcher-and-alert/215708>\
**Category:** Elasticsearch\
**Created:** [January 20, 2020, 10:14am UTC](https://discuss.elastic.co/t/brute-force-watcher-and-alert/215708 "2020-01-20T10:14:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdp](https://avatars.discourse-cdn.com/v4/letter/m/2acd7d/32.png) [@mdp](https://discuss.elastic.co/u/mdp)\
**Post date:** [January 20, 2020, 10:14am UTC](https://discuss.elastic.co/t/brute-force-watcher-and-alert/215708/1 "2020-01-20T10:14:59Z")

</div>

Hi,

I am looking at support/advice on modifying a watcher to accomplish:

1. A single email and alert output for each occurrence where there a user has failed logins x times in x minutes.
2. The alert and email to contain a combination of Username, Source IP, Hostname (all of which are available in the records. (Only 1 alert per combination, if a second username is failing this should be a unique alert/email)

Currently we have the following which was created by a 3rd Party which did not satisfy the requirement.

{  
"trigger":  
{  
"schedule":  
{  
"interval": "5m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"acme-dbauth-_-v2"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": [  
{  
"match": {  
"event.action": "database\_login"  
}  
},  
{  
"match": {  
"event.outcome": "failure"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-5m"  
}  
}  
}  
]  
}  
},  
"aggs": {  
"failed\_logins": {  
"terms": {  
"field": "user.name",  
"size": 10  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": " def users = [];\n for (def uname : ctx.payload.aggregations.failed\_logins.buckets) {\n if (uname.doc\_count\>2) {\n users.add(uname.key);\n }\n }\n \n ctx.payload.users = users;\n \n ctx.payload.\_doc = [\n '@timestamp': ctx.execution\_time,\n 'alert\_id': ctx.watch\_id,\n 'cause\_index': 'acme-dbauth-_-v2',\n 'plain\_reason': 'Multiple failed logins from same user(s)',\n 'info1\_key': 'user\_names',\n 'info1\_val': users\n];\n \n return users.size()\>0;",  
"lang": "painless"  
}  
},  
"actions": {  
"send\_email": {  
"throttle\_period\_in\_millis": 1800000,  
"email": {  
"account": "exchange\_account",  
"profile": "standard",  
"to": [  
"[coyote@acme.com](mailto:coyote@acme.com)"  
],  
"subject": "Elastic Alert: dba\_brute\_force",  
"body": {  
"text": "Detected multiple failed logins from users: {{ctx.payload.users}}"  
}  
}  
},  
"index\_alert": {  
"index": {  
"index": "acme-dbauth-alerts"  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 20, 2020, 2:06pm UTC](https://discuss.elastic.co/t/brute-force-watcher-and-alert/215708/2 "2020-01-20T14:06:06Z")

</div>

Hi, you could try to iterate through hits with a transform script with a for loop for each item then you have to parse it as you need.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2020, 2:08pm UTC](https://discuss.elastic.co/t/brute-force-watcher-and-alert/215708/3 "2020-02-17T14:08:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
