# Put a rule that will allow me to detect brute force

**URL:** <https://discuss.elastic.co/t/put-a-rule-that-will-allow-me-to-detect-brute-force/319080>\
**Category:** Elasticsearch\
**Created:** [November 16, 2022, 12:40pm UTC](https://discuss.elastic.co/t/put-a-rule-that-will-allow-me-to-detect-brute-force/319080 "2022-11-16T12:40:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![buhu698](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/buhu698/32/113397_2.png) [@buhu698](https://discuss.elastic.co/u/buhu698)\
**Post date:** [November 16, 2022, 12:40pm UTC](https://discuss.elastic.co/t/put-a-rule-that-will-allow-me-to-detect-brute-force/319080/1 "2022-11-16T12:40:52Z")

</div>

Hello,  
can you help me to put a rule that will allow me to detect brute force.  
type of rule ( event correlation or indicator match ).  
From the Kali machine, I run the following command:

Hydra –L /usr/share/wordlists/metasploit/namelist.txt –P /usr/share/wordlists/metasploit/password.lst ```  
\<adresseIP\_machineUbuntu\>

```nohighlight
-I want to set up a rule that will detect similar activity (brute force).knowing that my beats agents are filebeat and packetbeat
Best regards
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2022, 12:41pm UTC](https://discuss.elastic.co/t/put-a-rule-that-will-allow-me-to-detect-brute-force/319080/2 "2022-12-14T12:41:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
