# Combine results from same IP

**URL:** <https://community.graylog.org/t/combine-results-from-same-ip/7232>\
**Category:** Graylog Central (peer support)\
**Created:** [October 12, 2018, 1:59pm UTC](https://community.graylog.org/t/combine-results-from-same-ip/7232 "2018-10-12T13:59:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![chake](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/chake/32/2842_2.png) [@chake](https://community.graylog.org/u/chake)\
**Post date:** [October 12, 2018, 1:59pm UTC](https://community.graylog.org/t/combine-results-from-same-ip/7232/1 "2018-10-12T13:59:33Z")

</div>

I would like to combine results from the same IP address. So lets say someone tries to do a brute force attack and after 20 attempts he found the correct password and can login. I would like to combine this login failures with the login accepted without adding an IP address in my query.

---

<div class="post-metadata">

**Author:** ![123dev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/123dev/32/865_2.png) [@123dev](https://community.graylog.org/u/123dev)\
**Post date:** [October 12, 2018, 5:56pm UTC](https://community.graylog.org/t/combine-results-from-same-ip/7232/2 "2018-10-12T17:56:21Z")

</div>

See if this could help

> **[Graylog](https://marketplace.graylog.org/addons/0d01a899-138a-4f77-a9e7-04be4cc5e190)**
>
> Graylog

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [October 26, 2018, 5:56pm UTC](https://community.graylog.org/t/combine-results-from-same-ip/7232/3 "2018-10-26T17:56:23Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
