I am trying to create an alert that triggers when the location field of a login event from a user changes. so if a user logged in from London earlier and then the next login comes from Dublin, I want an alert to trigger. The login event has a username and client.geoLocation.city field.
Assuming your search window is applicable for this kind of alert, you only need to count number of different client.geoLocation.city. Is this correct? Something like
| stats values(eval('client.geoLocation.city')) as geoLocations by username
| where mvcount(geoLocations) > 1
Assuming your search window is applicable for this kind of alert, you only need to count number of different client.geoLocation.city. Is this correct? Something like
| stats values(eval('client.geoLocation.city')) as geoLocations by username
| where mvcount(geoLocations) > 1