# Find users (IP adresses) which only access one group of servers

**URL:** <https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714>\
**Category:** Kibana\
**Created:** [March 28, 2023, 1:34pm UTC](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714 "2023-03-28T13:34:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![zebu14](https://avatars.discourse-cdn.com/v4/letter/z/aca169/32.png) [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Post date:** [March 28, 2023, 1:34pm UTC](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714/1 "2023-03-28T13:34:13Z")

</div>

Hello,  
I have two groups of forward proxies running Squid (2x 4 servers)  
Many users are using these proxies.  
A load balancer sends each new connection on a group or another.  
Some users are not using the load balancer as the entry point, so I want to find which ones.  
I don't have any access to the load-balancer or its logs.

My logs give me the client\_ip, timestamp and the proxy hostname

I want to find the IP adresses which only used a part of the proxy hosts over a defined duration (a week for example)

Do you have an idea on how about to proceed ?

I tried with a data table, using split rows for the proxy host and split tables for the IP, but the display is not user-friendly and I cannot export all the results, but only the results of each table...

Thank you

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [April 13, 2023, 1:53pm UTC](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714/2 "2023-04-13T13:53:41Z")

</div>

I tried a simplified version of your issue and got something to share. Maybe it is not exactly what you want but it may give you some pointers.

This is the data I used:

```auto
/* Clean up */
DELETE discuss-328714-data

/* Create a test index */
PUT discuss-328714-data
{
  "mappings": {
    "properties": {
      "ts": { "type": "date"},
      "ip": { "type": "keyword"},
      "proxy": { "type": "keyword"}
    }
  }
}

/* Add some data to the index */
POST discuss-328714-data/_bulk
{ "index": {}}
{"ts": "2023-03-13", "ip": "1.1.1.1", "proxy": "p1"}
{ "index": {}}
{"ts": "2023-03-14", "ip": "1.1.1.1", "proxy": "p1"}
{ "index": {}}
{"ts": "2023-03-15", "ip": "1.1.1.1", "proxy": "p1"}
{ "index": {}}
{"ts": "2023-03-16", "ip": "1.1.1.1", "proxy": "p1"}
{ "index": {}}
{"ts": "2023-03-13", "ip": "1.1.1.2", "proxy": "p1"}
{ "index": {}}
{"ts": "2023-03-14", "ip": "1.1.1.2", "proxy": "p2"}
{ "index": {}}
{"ts": "2023-03-15", "ip": "1.1.1.2", "proxy": "p1"}
{ "index": {}}
{"ts": "2023-03-16", "ip": "1.1.1.2", "proxy": "p2"}
{ "index": {}}
{"ts": "2023-03-13", "ip": "1.1.1.3", "proxy": "p2"}
{ "index": {}}
{"ts": "2023-03-14", "ip": "1.1.1.3", "proxy": "p2"}
{ "index": {}}
{"ts": "2023-03-15", "ip": "1.1.1.3", "proxy": "p2"}
{ "index": {}}
{"ts": "2023-03-16", "ip": "1.1.1.3", "proxy": "p2"}

```

So there is an index with a date, an IP, and a proxy identifier. I created a Data View on this index with the defaults.

Then in Lens I created a table

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/e/de3a3023474109b6b02c957df5b77a064a1a1a98.png)

These are the settings:

For rows I got the top values for IPs ranked by the ascending number of unique count on the `proxy.keyword` field so it lists first those hitting a single proxy

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/c/5ce4b4965da87e29ccab07a1744881010d12a045.png)

And then for the metric I again get the unique count for the proxy field adding a custom color ramp to render on green those with count 1 and in red those with count 2 or more, you get the idea.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f6539bd7ed64b37948fc49d204af041d53e2e165.png)

That's it! let me know if this helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2023, 1:54pm UTC](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714/3 "2023-05-11T13:54:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
