There are two fields in each log entry (elasticsearch document), which are userid and ipaddress. I want to fire an alert if the same user logs into the system using 2 or more ipaddresses in the past 10 minutes. So the query should be something like "select count(distinct ipaddress) from index group by userid".
But it seems that watcher doesn't support "distinct count", does anyone have any suggestion on how to resolve this? Thanks.