# GeoIP - how to only show users who are or have logged on from multiple locations

**URL:** <https://discuss.elastic.co/t/geoip-how-to-only-show-users-who-are-or-have-logged-on-from-multiple-locations/266817>\
**Category:** Kibana\
**Created:** [March 10, 2021, 2:06pm UTC](https://discuss.elastic.co/t/geoip-how-to-only-show-users-who-are-or-have-logged-on-from-multiple-locations/266817 "2021-03-10T14:06:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![FinT](https://avatars.discourse-cdn.com/v4/letter/f/8dc957/32.png) [@FinT](https://discuss.elastic.co/u/FinT)\
**Post date:** [March 10, 2021, 2:06pm UTC](https://discuss.elastic.co/t/geoip-how-to-only-show-users-who-are-or-have-logged-on-from-multiple-locations/266817/1 "2021-03-10T14:06:33Z")

</div>

elastic stack 6.5.1. This question can be applied to any similar query to filter events.

I have visualised users (donut) who have logged in remotely. The inner ring shows users, the outer shows countries. Due to the large number of users, I have two views the the same data, UK and non-UK, but I would like to have one that only shows users who have remotely connected from more than country/city. Of course, this does show users who have multiple coloured outer ring segment, meaning multiple countries.

The raw data is similar to

userA "ip address 1.2.3.4" "country01" "100 times"  
userA "ip address 2.3.4.5" "country02" "30 times"  
userB "ip address 3.4.5.6" "country03" "2098 times"

I want to filter only users with multiple countries.

![donut](https://us1.discourse-cdn.com/elastic/original/3X/a/f/afcb2229b0b3db62cdfee882a2e6a9c40064ca56.jpeg)

Thanks for your time.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [March 11, 2021, 12:49am UTC](https://discuss.elastic.co/t/geoip-how-to-only-show-users-who-are-or-have-logged-on-from-multiple-locations/266817/2 "2021-03-11T00:49:45Z")

</div>

Hmm - it may be difficult without reorganizing the data. We would need a way to join documents - where usernames match. If we can get all the IP data in the same document then we would have options for creating a flag to filter on.

Without changing the source data, maybe something like a terms aggregation on user and `{ min_doc_count: 2 }` in the Advanced -\> JSON Input section may help.

---

<div class="post-metadata">

**Author:** ![FinT](https://avatars.discourse-cdn.com/v4/letter/f/8dc957/32.png) [@FinT](https://discuss.elastic.co/u/FinT)\
**Post date:** [March 11, 2021, 10:30am UTC](https://discuss.elastic.co/t/geoip-how-to-only-show-users-who-are-or-have-logged-on-from-multiple-locations/266817/3 "2021-03-11T10:30:56Z")

</div>

Thanks for your insight Jon. Appreciated.

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [March 13, 2021, 5:50pm UTC](https://discuss.elastic.co/t/geoip-how-to-only-show-users-who-are-or-have-logged-on-from-multiple-locations/266817/4 "2021-03-13T17:50:35Z")

</div>

You could add the information you want using a transform. The resulting index can be used to visualize the data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2021, 5:50pm UTC](https://discuss.elastic.co/t/geoip-how-to-only-show-users-who-are-or-have-logged-on-from-multiple-locations/266817/5 "2021-04-10T17:50:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
