# Siem Rule to detect ssh login with multiple source address

**URL:** https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718
**Category:** SIEM
**Created:** [September 7, 2020, 7:10am UTC](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718 "2020-09-07T07:10:09Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![madduck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madduck/32/63444_2.png) [@madduck](https://discuss.elastic.co/u/madduck)
#### Post date: [September 7, 2020, 12:29pm UTC](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718/2 "2020-09-07T12:29:15Z")

</div>

Hi Kambing,

What you are trying to do is not possible with the static detection rules. You might want to look into Machine Learning rules.

A similar question was asked two weeks ago, if you want to read a bit here is a link:

> [@SIEM Threshold - unique values](https://discuss.elastic.co/t/siem-threshold-unique-values/246606):
>
> Hi I am playing with the SIEM capability and have been using it since it was released with custom queries. I am now looking at Threshold based detection in v7.9 - something I think will be very useful. I'm not sure if this is possible at the moment or a future capability but is there a method of the threshold considering aggregations and unique values? There are a few use cases but as an example, I would like to know if a user connects inbound over the VPN from multiple locations. So if I l…

---

_[View the full topic](https://discuss.elastic.co/t/siem-rule-to-detect-ssh-login-with-multiple-source-address/247718)._
