# Query - Find all ip visiting multiple differents servers

**URL:** <https://discuss.elastic.co/t/query-find-all-ip-visiting-multiple-differents-servers/1216>\
**Category:** Elasticsearch\
**Created:** [May 23, 2015, 9:08pm UTC](https://discuss.elastic.co/t/query-find-all-ip-visiting-multiple-differents-servers/1216 "2015-05-23T21:08:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexis/32/44779_2.png) [@alexis](https://discuss.elastic.co/u/alexis)\
**Post date:** [May 23, 2015, 9:08pm UTC](https://discuss.elastic.co/t/query-find-all-ip-visiting-multiple-differents-servers/1216/1 "2015-05-23T21:08:39Z")

</div>

Hello guys,

I'm new here and I discovered the ELK stack a few days ago. I managed to parse all my webserver logs and now I'm having fun with elasticSearch to perform some research.

Right now I have a query idea but I really don't now how I can do it, mostly because I'm not famililiar with the ElasticSearch vocabolary so it's difficult for me to search the right stuff.

In my logs and ElasticSearch DB, I have a field for the visitor IP address and another field for the webserver name. I have multiple servers and I want to find all IPs that visit at least 2 websites hosted on differents servers.

The idea is to detect all IP accessing different servers within a reasonable period of time, I think it's interesting in a security point of view because I'm pretty sure I'll find a lot of servers scans.

Is it possible to do such things with ES ? How can I do that ? (how is this called at least ? like I said, i'm not familiar with the vocabular of ES yet).

Thank in advance,  
Have a great day,  
Alexis

---

<div class="post-metadata">

**Author:** ![Jason\_Wee](https://avatars.discourse-cdn.com/v4/letter/j/7ea924/32.png) [@Jason\_Wee](https://discuss.elastic.co/u/Jason_Wee)\
**Post date:** [May 25, 2015, 1:12pm UTC](https://discuss.elastic.co/t/query-find-all-ip-visiting-multiple-differents-servers/1216/2 "2015-05-25T13:12:24Z")

</div>

have you try range query? [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html)

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [May 25, 2015, 2:01pm UTC](https://discuss.elastic.co/t/query-find-all-ip-visiting-multiple-differents-servers/1216/3 "2015-05-25T14:01:28Z")

</div>

I think you would like to look up the following concepts:

- period of time: range filter
- break down by ip: terms aggregation
- count unique servers: cardinality aggregation

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:12am UTC](https://discuss.elastic.co/t/query-find-all-ip-visiting-multiple-differents-servers/1216/4 "2017-07-06T00:12:05Z")

</div>


