Alert eventid and ip source.How to have corelation

Hello

I programmed an alert when on my stream has 5 eventid 4625 on 5minute I would like to add a condition that it comes from the same ip source.

how i can do that ?

Nobody know how to do that

This is a community forum in which people are helping in their free time. You cannot expect to get an answer or even a reply within a given time.

If you want authoritative answers within a certain time, you’ll have to buy professional support:
https://www.graylog.org/pricing

Ok thank you, have nice day

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.