# Creating a threshold based rule in the detection engine

**URL:** <https://discuss.elastic.co/t/creating-a-threshold-based-rule-in-the-detection-engine/270941>\
**Category:** SIEM\
**Tags:** elastic-stack-alerting\
**Created:** [April 22, 2021, 9:35am UTC](https://discuss.elastic.co/t/creating-a-threshold-based-rule-in-the-detection-engine/270941 "2021-04-22T09:35:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [April 22, 2021, 9:35am UTC](https://discuss.elastic.co/t/creating-a-threshold-based-rule-in-the-detection-engine/270941/1 "2021-04-22T09:35:40Z")

</div>

I'm managing logs of a particular server, I'm defining an activity of a person with some username to be suspicious if there is sudden increase in their activity( i.e., user logs into server 100 times whereas on average he logs in less than half \<50).

Help me creating a threshold based rule in the detection engine. If this is not possible by this, suggest me a way. My logs looks like this:

```auto
10.0.0.10 - username [21/Sep/2020:04:27:18 +0000] "GET /svn/repos HTTP/1.1" 200 289

```

I this task achievable by elastalert if not here?

---

<div class="post-metadata">

**Author:** ![Oliver2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oliver2/32/76684_2.png) [@Oliver2](https://discuss.elastic.co/u/Oliver2)\
**Post date:** [April 27, 2021, 10:18pm UTC](https://discuss.elastic.co/t/creating-a-threshold-based-rule-in-the-detection-engine/270941/2 "2021-04-27T22:18:28Z")

</div>

machine learning might be able to achieve yhis

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [April 28, 2021, 2:51pm UTC](https://discuss.elastic.co/t/creating-a-threshold-based-rule-in-the-detection-engine/270941/3 "2021-04-28T14:51:06Z")

</div>

> [@abhishek\_s1](#):
>
> I'm managing logs of a particular server, I'm defining an activity of a person with some username to be suspicious if there is sudden increase in their activity( i.e., user logs into server 100 times whereas on average he logs in less than half \<50).

Yes this would be best solved with a Machine Learning rule, because Elastic doesn't do baselining and trigger rules based on going above the baseline. So Machine learning will be your best bet. You should join the slack for a quicker response [Join Elastic Stack Community on Slack - Community Inviter](https://ela.st/slack).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2021, 2:51pm UTC](https://discuss.elastic.co/t/creating-a-threshold-based-rule-in-the-detection-engine/270941/4 "2021-05-26T14:51:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
