# Logged in from more than one IP address at same time

**URL:** <https://discuss.elastic.co/t/logged-in-from-more-than-one-ip-address-at-same-time/66864>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 22, 2016, 2:00pm UTC](https://discuss.elastic.co/t/logged-in-from-more-than-one-ip-address-at-same-time/66864 "2016-11-22T14:00:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rajasekaran\_Mari](https://avatars.discourse-cdn.com/v4/letter/r/53a042/32.png) [@Rajasekaran\_Mari](https://discuss.elastic.co/u/Rajasekaran_Mari)\
**Post date:** [November 22, 2016, 2:00pm UTC](https://discuss.elastic.co/t/logged-in-from-more-than-one-ip-address-at-same-time/66864/1 "2016-11-22T14:00:51Z")

</div>

We use cloudtrail to log AWS user login and the cloudtrail logs been configured in ELK and indexed. I'm writing a watcher script to query and fetch user information for the following condition:

When multiple login found for the same user (logged in from more than one IP address at same time in this case), watcher will trigger email notification. Query should return the user name and the list of IP's from which the user logged in.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 23, 2016, 2:44pm UTC](https://discuss.elastic.co/t/logged-in-from-more-than-one-ip-address-at-same-time/66864/2 "2016-11-23T14:44:14Z")

</div>

this is a duplicate. Closing
