# Injecting malicious IP list to compare against active connections and alert if found - Use case

**URL:** <https://discuss.elastic.co/t/injecting-malicious-ip-list-to-compare-against-active-connections-and-alert-if-found-use-case/159610>\
**Category:** Kibana\
**Created:** [December 5, 2018, 10:07pm UTC](https://discuss.elastic.co/t/injecting-malicious-ip-list-to-compare-against-active-connections-and-alert-if-found-use-case/159610 "2018-12-05T22:07:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ciphee](https://avatars.discourse-cdn.com/v4/letter/c/90ced4/32.png) [@ciphee](https://discuss.elastic.co/u/ciphee)\
**Post date:** [December 5, 2018, 10:07pm UTC](https://discuss.elastic.co/t/injecting-malicious-ip-list-to-compare-against-active-connections-and-alert-if-found-use-case/159610/1 "2018-12-05T22:07:05Z")

</div>

Hi there,

I was trying to setup a usecase to do the following:

1.) Download a txt file containing known malicious IP's.  
2.) Compare existing netflow traffic logs to see if there is a match against any of the malicious IP's  
3.) Send an alert if a connection is found with these malicious IP's.

Is this possible to do?

Thank you for any assistance.

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [December 6, 2018, 10:45am UTC](https://discuss.elastic.co/t/injecting-malicious-ip-list-to-compare-against-active-connections-and-alert-if-found-use-case/159610/2 "2018-12-06T10:45:57Z")

</div>

is this the same as [Use Case: Upload to rare external IP](https://discuss.elastic.co/t/use-case-upload-to-rare-external-ip/159615) or are this two different use cases ?

---

<div class="post-metadata">

**Author:** ![ciphee](https://avatars.discourse-cdn.com/v4/letter/c/90ced4/32.png) [@ciphee](https://discuss.elastic.co/u/ciphee)\
**Post date:** [December 6, 2018, 5:46pm UTC](https://discuss.elastic.co/t/injecting-malicious-ip-list-to-compare-against-active-connections-and-alert-if-found-use-case/159610/3 "2018-12-06T17:46:31Z")

</div>

That link is for creating a use case that involves this step, this thread is only for that one step of injecting a list into elastic. This step can be applied in many use cases.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2019, 5:46pm UTC](https://discuss.elastic.co/t/injecting-malicious-ip-list-to-compare-against-active-connections-and-alert-if-found-use-case/159610/4 "2019-01-03T17:46:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
