# EQL - Alert on different values for the same field in a sequence

**URL:** https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344
**Category:** Elastic Security
**Created:** [November 13, 2020, 1:08pm UTC](https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344 "2020-11-13T13:08:52Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [November 13, 2020, 1:08pm UTC](https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344/1 "2020-11-13T13:08:52Z")

</div>

Hi,

I am trying to build a sequence, as an example to look for multiple different user.names from the same host over a period of time. How would i go about this condition 2 user.name != condition 1 user.name. There a number of scenarios this would be useful for, i have looked through the documentation but cannot find what i am looking for.

```auto
    sequence by source.ip with maxspan=30s
      [authentication where event.action:"logon-failed" and source.ip != "127.0.0.1"]
      [authentication where event.action:"logon-failed" and source.ip != "127.0.0.1"]

```

Thanks  
Phil

---

<div class="post-metadata">

### Author: ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)
#### Post date: [November 16, 2020, 3:34pm UTC](https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344/2 "2020-11-16T15:34:35Z")

</div>

hi @probson, glad to see you're using EQL.

With the EQL as of 7.10, there's no way to do the `!=` check, but you can use `by` for the `==` check. What you're looking for will depend on the `filter` pipe, which is not yet implemented in Elasticsearch.

If you want to see some examples of how the `filter` pipe works for Elastic Endgame, [here is its documentation](https://eql.readthedocs.io/en/latest/query-guide/pipes.html#filter).

---

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [November 16, 2020, 3:49pm UTC](https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344/3 "2020-11-16T15:49:44Z")

</div>

@rw-access

That looks good so in theory we should be able to do the below when the filter pipe is released?

| filter events[0].user.name != events[1].user.name

---

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [November 23, 2020, 4:13pm UTC](https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344/4 "2020-11-23T16:13:50Z")

</div>

looks like unique\_count is what i would be really looking at, hopefully that will be implemented as well.

Thanks

---

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [March 10, 2021, 11:29am UTC](https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344/5 "2021-03-10T11:29:05Z")

</div>

@rw-access

Hi there, any update on when we might see the more advanced EQL pipes such as filter and unique\_count?

---

<div class="post-metadata">

### Author: ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)
#### Post date: [March 10, 2021, 6:13pm UTC](https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344/6 "2021-03-10T18:13:39Z")

</div>

Hi @probson,

I think at this point, it's best to treat Endgame EQL as separate, and not a roadmap for Elasticsearch EQL.

We are exploring options to see if there's a better way to address this use case within our outside of EQL.

One feature that's [under development](https://github.com/elastic/kibana/pull/90826) is adding a concept of cardinality to threshold rules within the detection engine. Within that you'll be able to say this:

- Group by `source.ip`
- Limit to groups with at least `2` documents
- Make sure there are at least `2` unique values for `user.name`

I think when that functionality is available, it'll be the best way to solve your current use case.

---

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [March 10, 2021, 6:33pm UTC](https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344/7 "2021-03-10T18:33:41Z")

</div>

@rw-access

Cardinality would be very nice to have, i used it with ElastAlert in the past. At the moment ive been trying to look at using ML and the high\_distinct\_count to do something similar.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 4, 2022, 8:17am UTC](https://discuss.elastic.co/t/eql-alert-on-different-values-for-the-same-field-in-a-sequence/255344/8 "2022-11-04T08:17:36Z")

</div>


