Siem Rule to detect ssh login with multiple source address

Hi Kambing,

What you are trying to do is not possible with the static detection rules. You might want to look into Machine Learning rules.

A similar question was asked two weeks ago, if you want to read a bit here is a link:

1 Like