# Detection of a behavior preceded or followed by an event type

**URL:** <https://discuss.elastic.co/t/detection-of-a-behavior-preceded-or-followed-by-an-event-type/281127>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [August 11, 2021, 10:09pm UTC](https://discuss.elastic.co/t/detection-of-a-behavior-preceded-or-followed-by-an-event-type/281127 "2021-08-11T22:09:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Post date:** [August 11, 2021, 10:09pm UTC](https://discuss.elastic.co/t/detection-of-a-behavior-preceded-or-followed-by-an-event-type/281127/1 "2021-08-11T22:09:32Z")

</div>

Hello every body,

I have a question about the rule’s creation , Is it possible to have rules with these conditions, if yes how?

- More than 40 events with event.action:”block” from the same IP address followed or preceded by event.action:”autorized”

Best regards,

---

<div class="post-metadata">

**Author:** ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)\
**Post date:** [August 23, 2021, 3:45pm UTC](https://discuss.elastic.co/t/detection-of-a-behavior-preceded-or-followed-by-an-event-type/281127/2 "2021-08-23T15:45:52Z")

</div>

There are two ways that come to mind, both use EQL [sequences](https://www.elastic.co/guide/en/elasticsearch/reference/current/eql-syntax.html#eql-sequences):

1. Create a building block rule plus a sequence of two events:

First, create a [building block rule](https://www.elastic.co/guide/en/security/current/building-block-rule.html) to look for \>= 40 events with `event.action: "block"`.

Then, create an EQL sequence rule that looks for a sequence of your building block alert, followed by `authorized`:

```auto
sequence by source.ip
  [any where rule.name : "your building block rule" and ...]
  [any where event.action == "authorized"]

```

1. Create a single EQL sequence for everything. You'll want to make it more specific than what I have below, but it's a start.

```auto
sequence by source.ipd
  [any where event.action == "block"] // 1
  [any where event.action == "block"] // 2
  // ...
  [any where event.action == "block"] // 39
  [any where event.action == "block"] // 40
  [any where event.action == "authorized"]

```

We are actively talking about new syntax to make it easier to write the 40 repetitive terms, so I would expect this to get easier to write in the future.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2021, 3:46pm UTC](https://discuss.elastic.co/t/detection-of-a-behavior-preceded-or-followed-by-an-event-type/281127/3 "2021-09-20T15:46:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
