# Siem Rule to detect ssh login with multiple source address

**URL:** https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718
**Category:** SIEM
**Created:** [September 7, 2020, 7:10am UTC](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718 "2020-09-07T07:10:09Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Kambing](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kambing/32/45151_2.png) [@Kambing](https://discuss.elastic.co/u/Kambing)
#### Post date: [September 7, 2020, 7:10am UTC](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718/1 "2020-09-07T07:10:09Z")

</div>

Hi, I'm new with Elastic SIEM and now I need to create a rule to detect ssh successful login with multiple IP address with the same username. I wonder how can I create a rule like this since if I using Custon Query or Threshold type, it will be stick to 1 IP only.

filebaet and auditbeat is running already on the server and I can see SSH logs in the discovery

Thank you

---

<div class="post-metadata">

### Author: ![madduck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madduck/32/63444_2.png) [@madduck](https://discuss.elastic.co/u/madduck)
#### Post date: [September 7, 2020, 12:29pm UTC](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718/2 "2020-09-07T12:29:15Z")

</div>

Hi Kambing,

What you are trying to do is not possible with the static detection rules. You might want to look into Machine Learning rules.

A similar question was asked two weeks ago, if you want to read a bit here is a link:

> [@SIEM Threshold - unique values](https://discuss.elastic.co/t/siem-threshold-unique-values/246606):
>
> Hi I am playing with the SIEM capability and have been using it since it was released with custom queries. I am now looking at Threshold based detection in v7.9 - something I think will be very useful. I'm not sure if this is possible at the moment or a future capability but is there a method of the threshold considering aggregations and unique values? There are a few use cases but as an example, I would like to know if a user connects inbound over the VPN from multiple locations. So if I l…

---

<div class="post-metadata">

### Author: ![Kambing](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kambing/32/45151_2.png) [@Kambing](https://discuss.elastic.co/u/Kambing)
#### Post date: [September 9, 2020, 8:23am UTC](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718/3 "2020-09-09T08:23:04Z")

</div>

Hi Madduck,

Thanks for the reply  
currently I'm trying to use painless script to compare if there's a login with same username but with different IP. however, I still have no clue how to do loop through all documents in that index.

I also think to create new pipeline and add script in the processors so only the new log that will do the lookup throughout current existing documents.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 7, 2020, 8:23am UTC](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718/4 "2020-10-07T08:23:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
