One alert for all unique event.action from all events in last 30mins

Version: ELK 7.13
Need to generate a single alert for all events with unique event.action feild values in last 30minute.

Can someone please let me know which rule type I can use here? Also please share if you have any sample.

I have tried following without success.

  1. Threshold rule Detection - But here I have to give a threshold number and unique value number, in my actual requirement there is no such number limit.

  2. Custom Rule: There is no option to aggregate/group by one field and send alert based on this.

Thanks in advance.

What if you do this?