# I want to create alert for same Source-ip and same destination-ip but different port

**URL:** <https://discuss.elastic.co/t/i-want-to-create-alert-for-same-source-ip-and-same-destination-ip-but-different-port/202816>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 9, 2019, 10:49am UTC](https://discuss.elastic.co/t/i-want-to-create-alert-for-same-source-ip-and-same-destination-ip-but-different-port/202816 "2019-10-09T10:49:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tahseen\_fatima](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tahseen_fatima/32/67789_2.png) [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)\
**Post date:** [October 9, 2019, 10:49am UTC](https://discuss.elastic.co/t/i-want-to-create-alert-for-same-source-ip-and-same-destination-ip-but-different-port/202816/1 "2019-10-09T10:49:41Z")

</div>

Hello,  
My question is `Trigger alert when Sourc-ip and Destination-ip is same but different destination port trigger alert`

and I am facing problem here is my configuration.

```
PUT _xpack/watcher/watch/vertical-port-scan
{
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "input" : {
    "search" : {
      "request" : {
        "indices" : [
          "firewall-vertical-port-scan"
        ],
        "body" : {
          "query" : {
            "bool" : {
              "must": [
                {
           "terms": {
        "field": "dstPort.keyword"
                  },
                  "bool": {
      "must": [
        {
          "match_phrase": {
            "srcIp.keyword": {
              "query": "20.36.219.28"
            }
          }
        },
        {
          "match_phrase": {
            "dstIp.keyword": {
              "query": "10.18.13.85"
            }
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": 1562856683309,
              "lte": 1570632683309,
              "format": "epoch_millis"
            }
          }
        }
        ],
      "filter": [
        {
          "match_all": {}
        },
        {
          "match_all": {}
        }
      ],
      "should": [],
      "must_not": []
    }
                },
                {
        }
              ]
              }
          }
        }
      }
    }
  },
  "condition" : {
    "compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}
  },
  "throttle_period": "15m",
  "actions" : {
    "email_admin" : {
      "email" : {
        "to" : ["abcd@xyz.com"],
        "subject" : "abcd",
        "body": {
      "text": "TimeStamp:{{#ctx.payload.hits.hits}} {{_source.@timestamp}} {{/ctx.payload.hits.hits}}"

    }
      }
    }
  }
}

```

But is is giving error  
kindly help.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 9, 2019, 1:04pm UTC](https://discuss.elastic.co/t/i-want-to-create-alert-for-same-source-ip-and-same-destination-ip-but-different-port/202816/2 "2019-10-09T13:04:09Z")

</div>

please take your time to properly write up the issue you are having. Just pasting a watch is not enough. Explain your use-case, what problem you are trying to solve, why you picked a certain query, and also what expectations you have, that are not satisfied with your query. Also include sample documents that should match (and also not match) your query, so other people reading this have the chance to understand what you are after.

Thanks!

---

<div class="post-metadata">

**Author:** ![tahseen\_fatima](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tahseen_fatima/32/67789_2.png) [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)\
**Post date:** [October 10, 2019, 6:12am UTC](https://discuss.elastic.co/t/i-want-to-create-alert-for-same-source-ip-and-same-destination-ip-but-different-port/202816/3 "2019-10-10T06:12:56Z")

</div>

Hi,  
My use case is.  
I am having a log file of Firewall. In this I have a log like this:

> Aug 22 2019 13:17:05: %ASA-6-106100: access-list CheckPoint\_access\_in denied tcp CheckPoint/20.36.219.28(443) -\> Intranet-DMZ/10.18.13.85(55460) hit-cnt 1 first hit [0x14fc4bcc, 0x00000000]

This is my parser:

> %{SYSLOGTIMESTAMP:timeStamp}: %{DATA:data}: %{DATA:msg}/%{IP:srcIp}(%{NUMBER:srcPort}) -\> Intranet-DMZ/%{IP:dstIp}(%{NUMBER:dstPort})%{GREEDYDATA:remain}

From this I have to extract these field source-ip, Destination Ip and destination port.  
according to my use case I have to trigger an alert when the source ip and destination ip is same but they have different port trigger alert.

Kindly help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2019, 6:21am UTC](https://discuss.elastic.co/t/i-want-to-create-alert-for-same-source-ip-and-same-destination-ip-but-different-port/202816/4 "2019-11-07T06:21:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
