# Watcher: Usecase: how to find users logging in from different locations using watcher?

**URL:** <https://discuss.elastic.co/t/watcher-usecase-how-to-find-users-logging-in-from-different-locations-using-watcher/33813>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 4, 2015, 9:41pm UTC](https://discuss.elastic.co/t/watcher-usecase-how-to-find-users-logging-in-from-different-locations-using-watcher/33813 "2015-11-04T21:41:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fatema](https://avatars.discourse-cdn.com/v4/letter/f/a587f6/32.png) [@Fatema](https://discuss.elastic.co/u/Fatema)\
**Post date:** [November 4, 2015, 9:41pm UTC](https://discuss.elastic.co/t/watcher-usecase-how-to-find-users-logging-in-from-different-locations-using-watcher/33813/1 "2015-11-04T21:41:41Z")

</div>

Hi ,

I am pretty new to Watcher, and I had a curious use-case, I want to know if a user is logging into the machine from different geo-locations. I have the users logging info already dumped into ES and can see the logs on Kibana4. I have geoip plugin enabled for that index so I get the different geo-locations from where the users are logging into the machine. I can pick a user from the user Field I have in kibana for that Type of logs and can filter logs on that user, and finally can find out the logging in geo-locations for that user on Kibana.

I wanted to figure out a way that watcher can alert whenever it sees any user successfully logged in from multiple locations in a fixed period of time. I know the basic structure of Watcher (trigger, input, condition and action), furthermore I can also search for "SUCCESSFUL LOGINS" from ES but how can i use the list of users returned from the search , to iterate through each user and see the geo-location of login and if a user has logged in from different locations produce an alert?  
Is there a way in watcher where I can use the returned payload from a search, iterate through it and perform a condition check on other fields (geo-location in this case) and perform an action?

Thanks.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 30, 2015, 6:21am UTC](https://discuss.elastic.co/t/watcher-usecase-how-to-find-users-logging-in-from-different-locations-using-watcher/33813/2 "2015-11-30T06:21:32Z")

</div>

Hey,

the main question here seems to be, if you can write a query that returns the data needed. This depends on your data. Maybe you can write a query to get currently logged in users and run a terms aggregation on top with a `min_count` of 2, but this highly depends how your data looks like.

So, try to develop a working query first, that returns parseable results and then think about watcher and triggering.

Hope this makes sense.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/watcher-usecase-how-to-find-users-logging-in-from-different-locations-using-watcher/33813/3 "2017-07-06T13:48:03Z")

</div>


