# Query for an event that happens X times within a given timerange

**URL:** <https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550>\
**Category:** Kibana\
**Created:** [August 10, 2023, 10:51am UTC](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550 "2023-08-10T10:51:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![blacklistme](https://avatars.discourse-cdn.com/v4/letter/b/919ad9/32.png) [@blacklistme](https://discuss.elastic.co/u/blacklistme)\
**Post date:** [August 10, 2023, 10:51am UTC](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550/1 "2023-08-10T10:51:23Z")

</div>

Hi,

as the title already suggests, I am looking for a way in Kibana to generate an Seucurity-Alert, if one event ouccures x times within a given timespan.

Example: Five Failed logins on a system within 5 Minutes

I´ve tried it with a Threshold-Rule, but as far as I can see, it is not pissible to define a timerange. My second attempt was to create a Correlation-Rule, as this rules type can have a "maxspan" which defines the timerange to look at. Unfortunatally "maxspan" can only be used in conjuction with "sequence". And I don´t have a sequence 🙂

Basic license, so watcher is not available.

I would be very happy about support from you.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 10, 2023, 12:32pm UTC](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550/2 "2023-08-10T12:32:19Z")

</div>

> [@blacklistme](#):
>
> I´ve tried it with a Threshold-Rule, but as far as I can see, it is not pissible to define a timerange.

Are you talking about the [logs threshold rule](https://www.elastic.co/guide/en/observability/current/logs-threshold-alert.html)? If so, you can define the range in the _FOR THE LAST_ option, this is the lookback time.

If you set _FOR THE LAST_ to 5 minutes, this means that when the rule is triggered it will look back 5 minutes to see if it matches.

If set this rule to run every 4 minutes and lookback 5 minutes you will always be looking into a window of 5 minutes.

---

<div class="post-metadata">

**Author:** ![blacklistme](https://avatars.discourse-cdn.com/v4/letter/b/919ad9/32.png) [@blacklistme](https://discuss.elastic.co/u/blacklistme)\
**Post date:** [August 10, 2023, 3:03pm UTC](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550/3 "2023-08-10T15:03:19Z")

</div>

If I have understood it correctly, "logs threshold rules" are for log monitoring (or something like that). Or is it possible to create alerts from Securirity-app based on logs trhreshold rules?

The Use case seems to be an easy one (exampel):

- A Firewall sends event and traffic informations via filebeat to elastic
- Somebody enters a wrong password on the Firewall five times within 5 minutes
- Kibana Security Rule was triggerd

Any Ideas?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 10, 2023, 3:17pm UTC](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550/4 "2023-08-10T15:17:51Z")

</div>

> [@blacklistme](#):
>
> If I have understood it correctly, "logs threshold rules" are for log monitoring (or something like that). Or is it possible to create alerts from Securirity-app based on logs trhreshold rules?

Yeah, you are right, sorry for the confusion.

But I don't think you need to change anything in this case.

For example, if you set your rule schedule to run every 5 minutes, it will always look for the data in the past 5 minutes, basically it will look into `now -5m` and since it also has a per default additional look back time of 1m, it will in fact look into `now -6m`

Per [the documentation](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#rule-schedule) you have this:

> For example, if you set a rule to run every 5 minutes with an additional look-back time of 1 minute, the rule runs every 5 minutes but analyzes the documents added to indices during the last 6 minutes.

And also

> It is recommended to set the `Additional look-back time` to at least 1 minute. This ensures there are no missing alerts when a rule does not run exactly at its scheduled time.

So this will fit the use case you described.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2023, 3:18pm UTC](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550/5 "2023-09-07T15:18:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
