# Network Scan

**URL:** <https://discuss.elastic.co/t/network-scan/322835>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [January 10, 2023, 12:41pm UTC](https://discuss.elastic.co/t/network-scan/322835 "2023-01-10T12:41:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gurban](https://avatars.discourse-cdn.com/v4/letter/g/ba8739/32.png) [@Gurban](https://discuss.elastic.co/u/Gurban)\
**Post date:** [January 10, 2023, 12:41pm UTC](https://discuss.elastic.co/t/network-scan/322835/1 "2023-01-10T12:41:20Z")

</div>

How should I write Elastic rule that detect if more than 10 unique destinations were accessed from same source IP within 1 minutes.

Best Regards

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [January 12, 2023, 4:03pm UTC](https://discuss.elastic.co/t/network-scan/322835/2 "2023-01-12T16:03:14Z")

</div>

Hi @Gurban , this would be a very straightforward threshold rule. It would look something like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5bd1b3db4eafa9fb69b2bc9a57e8acba10df616a.jpeg)

Let me know if you need help with anything else.

---

<div class="post-metadata">

**Author:** ![Gurban](https://avatars.discourse-cdn.com/v4/letter/g/ba8739/32.png) [@Gurban](https://discuss.elastic.co/u/Gurban)\
**Post date:** [January 12, 2023, 4:47pm UTC](https://discuss.elastic.co/t/network-scan/322835/3 "2023-01-12T16:47:17Z")

</div>

if I want to convert this rule to a port scan rule then I have to change destination.ip to destination.port in the count field?

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [January 12, 2023, 5:22pm UTC](https://discuss.elastic.co/t/network-scan/322835/4 "2023-01-12T17:22:45Z")

</div>

That's right! You might also want to exclude some IPs in the query bar, such as 127.0.0.1/localhost etc.

---

<div class="post-metadata">

**Author:** ![Gurban](https://avatars.discourse-cdn.com/v4/letter/g/ba8739/32.png) [@Gurban](https://discuss.elastic.co/u/Gurban)\
**Post date:** [January 12, 2023, 5:34pm UTC](https://discuss.elastic.co/t/network-scan/322835/5 "2023-01-12T17:34:08Z")

</div>

Last question. What if I want to write these rules with EQL ? I need example.

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [January 12, 2023, 5:43pm UTC](https://discuss.elastic.co/t/network-scan/322835/6 "2023-01-12T17:43:35Z")

</div>

It's not possible at the moment. We cannot perform unique aggregations with EQL.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2023, 5:43pm UTC](https://discuss.elastic.co/t/network-scan/322835/7 "2023-02-09T17:43:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
