Hi
I am looking for the users who login from two different countries within hour hour.
user Country signature
aqbc india authentication successful
USA authentication successful
time frame: 1 Hour
I want the query which shows me the successful authentication from two different countries against same user.
index=xaxto | iplocation src | stats count(Country) by user
Try this (assuming you have IP and user extracted to respective fields)
index=xaxto "authenticateion successful" | iplocation src | table _time user country | streamstats window=1 current=f values(country) as prevcountry values(_time) as prevtime | where NOT (prevcountry=country) AND prevtime-_time>3600 | table _time user country
I believe the last condition in where should be _time-prev_time<3600
thanks for your kind response. can you please explain your query.
thanks