index="*" tag=fw action=blocked
| stats values(dest) as dest by src
| eval dest = dest
| where dest > 10
Hi @andynina,
if you want to trigger your alert when an IP try reaches more than 100 distinct IPs and it's blocked, you could run:
index="*" tag=fw action=blocked
| stats dc(dest) AS dest BY src
| where dest>10
if instead you want to check the number of tries, you could run:
index="*" tag=fw action=blocked
| stats count BY src
| where count>10
Ciao.
Giuseppe