# \[Elastic Security/SIEM\] - Detect if a source IP contacts more destination IPs or more destination ports

**URL:** <https://discuss.elastic.co/t/elastic-security-siem-detect-if-a-source-ip-contacts-more-destination-ips-or-more-destination-ports/362850>\
**Category:** Elastic Security\
**Created:** [July 10, 2024, 8:00am UTC](https://discuss.elastic.co/t/elastic-security-siem-detect-if-a-source-ip-contacts-more-destination-ips-or-more-destination-ports/362850 "2024-07-10T08:00:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vowag](https://avatars.discourse-cdn.com/v4/letter/v/d26b3c/32.png) [@vowag](https://discuss.elastic.co/u/vowag)\
**Post date:** [July 10, 2024, 8:00am UTC](https://discuss.elastic.co/t/elastic-security-siem-detect-if-a-source-ip-contacts-more-destination-ips-or-more-destination-ports/362850/1 "2024-07-10T08:00:40Z")

</div>

Hi all,

I'm new to Elastic and I need to make a detection rule that detects if more than 200 unique destination IPs were accessed from same source IP  
and if more that 400 unique destination ports are accessed from same source IP.  
Is it possible in Kibana with a single rule? From Threshold rule documentation: "Nested fields are not supported for use with Group by."

A workaround was creating two different threshold rules:

**1st rule** :  
Custom Query:  
`source.ip: x.x.x.x/y and event.category : "network"`

Group by:  
`source.ip destination.ip >= 200`

**2nd rule:**  
Custom Query:  
`source.ip: x.x.x.x/y and event.category : "network"`  
Group by:  
`source.ip destination.port >= 400`

Is there any other workaround?  
If not, we need to work with 2 rules.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![isorokopud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/isorokopud/32/119989_2.png) [@isorokopud](https://discuss.elastic.co/u/isorokopud)\
**Post date:** [July 24, 2024, 11:15am UTC](https://discuss.elastic.co/t/elastic-security-siem-detect-if-a-source-ip-contacts-more-destination-ips-or-more-destination-ports/362850/2 "2024-07-24T11:15:33Z")

</div>

Hey @vowag, thanks for reaching out!

You can try [ES|QL rule type](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-esql-rule). Where you can build a query similar to this one

```auto
FROM source_index
| STATS ip_count = COUNT_DISTINCT(destination.ip), port_count = COUNT_DISTINCT(destination.port) BY host.name
| WHERE event.category == "network" AND ip_count > 200 AND port_count > 400

```

[Here](https://www.elastic.co/guide/en/elasticsearch/reference/current/esql.html) you can also find useful references to the ES|QL syntax, commands and examples.

Let us know if that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2024, 11:16am UTC](https://discuss.elastic.co/t/elastic-security-siem-detect-if-a-source-ip-contacts-more-destination-ips-or-more-destination-ports/362850/3 "2024-08-21T11:16:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
