# Detect user login with different IP address

**URL:** <https://discuss.elastic.co/t/detect-user-login-with-different-ip-address/361633>\
**Category:** Elastic Security\
**Created:** [June 18, 2024, 10:24am UTC](https://discuss.elastic.co/t/detect-user-login-with-different-ip-address/361633 "2024-06-18T10:24:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maeris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maeris/32/123964_2.png) [@Maeris](https://discuss.elastic.co/u/Maeris)\
**Post date:** [June 18, 2024, 10:24am UTC](https://discuss.elastic.co/t/detect-user-login-with-different-ip-address/361633/1 "2024-06-18T10:24:07Z")

</div>

Hello,  
Im seeking to implement alerting for a scenario, where I want to detect if a user logs in from a previously not used IP address. My logs come in the following format:

```auto
{"uuid":"7f8738fe72a2074a8f65f9587","created":"2024-06-15T10:40:59.377855Z","event_type":"auth_logged_in_with_username","message":"User testuser with full name Test authenticated successfully.","context":{"os":{"name":"Windows","version":"10"},"location":"pending","platform":{"name":"Windows","version":"10"},"user_uuid":"1f22f51e5d8383e12b9ae6a","ip_address":"192.168.13.13","user_agent":"Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0","user_is_staff":"False","user_username":"testuser","user_full_name":"Test","user_token_lifetime":"None"}}

```

So basically I want to do a search of my data with the context.user\_uuid and context.ip\_address fields and check if there were previous entries before, and generate an alert if there werent. I tried OpenSearch prior, and attempted to implement this same scenario but was not able to do so. Now I'm wondering how can I achieve something like this with Elastic.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2024, 10:24am UTC](https://discuss.elastic.co/t/detect-user-login-with-different-ip-address/361633/2 "2024-06-18T10:24:07Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance. See [What is OpenSearch and the OpenSearch Dashboard? | Elastic](https://www.elastic.co/elasticsearch/opensearch) for more details.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)\
**Post date:** [June 18, 2024, 10:54am UTC](https://discuss.elastic.co/t/detect-user-login-with-different-ip-address/361633/3 "2024-06-18T10:54:23Z")

</div>

Hi @Maeris , welcome to the community.

It looks like new terms detection rule could be a solution.

As per definition:

> - [**New terms**](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-new-terms-rule): Generates an alert for each new term detected in source documents within a specified time range. You can also detect a combination of up to three new terms (for example, a `host.ip` and `host.id` that have never been observed together before).

Here you can find how to create it: [Create a detection rule | Elastic Security Solution [8.14] | Elastic](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-new-terms-rule)

For you case, I think you would need to define `context.user_uuid` and `context.ip_address` fields as new terms in rule configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2024, 10:55am UTC](https://discuss.elastic.co/t/detect-user-login-with-different-ip-address/361633/4 "2024-07-16T10:55:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
