# ES|QL - span

**URL:** https://discuss.elastic.co/t/es-ql-span/364021
**Category:** Endpoint Security
**Tags:** elastic-stack-alerting
**Created:** [July 30, 2024, 5:10am UTC](https://discuss.elastic.co/t/es-ql-span/364021 "2024-07-30T05:10:02Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Marek\_Galbavy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marek_galbavy/32/132943_2.png) [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)
#### Post date: [July 30, 2024, 5:10am UTC](https://discuss.elastic.co/t/es-ql-span/364021/1 "2024-07-30T05:10:02Z")

</div>

Hi i create a new topic as a advice of your team:

I want to create a rule that will detect the upload of a large amount of data from my network. The rule works as I want, except that I have to run it every minute to group the data into minute blocks for each domain. My question is how to set it up so that I only need to run the rule once every 12 hours, with the upload data being calculated in minute blocks.

Here is my current query:  
from logs-\*  
| WHERE (CIDR\_MATCH(source.ip, "10.0.0.0/8") OR CIDR\_MATCH(source.ip, "172.16.0.0/12") OR CIDR\_MATCH(source.ip, "192.168.0.0/16")) and url.domain is not null and @timestamp \>= now() - 60seconds  
| stats upload = sum(source.bytes) by url.domain, source.ip  
| where upload \>= 52428800

eg in splunk exist command span so something like that

---

<div class="post-metadata">

### Author: ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)
#### Post date: [July 30, 2024, 5:36am UTC](https://discuss.elastic.co/t/es-ql-span/364021/2 "2024-07-30T05:36:26Z")

</div>

Hello Marek,

Could something like this work for you(untested)?

```auto
from logs-*
| WHERE (CIDR_MATCH(source.ip, "10.0.0.0/8") OR CIDR_MATCH(source.ip, "172.16.0.0/12") OR CIDR_MATCH(source.ip, "192.168.0.0/16")) and url.domain is not null and @timestamp >= now() - 12hours
| stats upload = sum(source.bytes) by url.domain, source.ip, minute = BUCKET(@timestamp, 1 minute)
| where upload >= 52428800

```

This will also group by the `@timestamp` splitting it into a histogramm of 1 minute intervals.

Best regards  
Wolfram

---

<div class="post-metadata">

### Author: ![Marek\_Galbavy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marek_galbavy/32/132943_2.png) [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)
#### Post date: [July 30, 2024, 6:19am UTC](https://discuss.elastic.co/t/es-ql-span/364021/3 "2024-07-30T06:19:56Z")

</div>

> [@Wolfram\_Haussig](#):
>
> `minute = BUCKET(@timestamp, 1 minute)`

HI, no that didnt work because Unknown function [BUCKET]

---

<div class="post-metadata">

### Author: ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)
#### Post date: [July 30, 2024, 6:27am UTC](https://discuss.elastic.co/t/es-ql-span/364021/4 "2024-07-30T06:27:14Z")

</div>

> [@Marek\_Galbavy](#):
>
> no that didnt work because Unknown function [BUCKET]

What version of the stack do you have? BUCKET became available with 8.14. If you have an earlier version, you may try using `AUTO_BUCKET`: [ES|QL functions and operators | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.11/esql-functions-operators.html#esql-auto_bucket)

---

<div class="post-metadata">

### Author: ![Marek\_Galbavy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marek_galbavy/32/132943_2.png) [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)
#### Post date: [July 30, 2024, 6:33am UTC](https://discuss.elastic.co/t/es-ql-span/364021/5 "2024-07-30T06:33:10Z")

</div>

v 8.13.2 so i try do ask colleque to upgrade to 8x14 and try the bucket, thx

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 27, 2024, 6:33am UTC](https://discuss.elastic.co/t/es-ql-span/364021/6 "2024-08-27T06:33:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
