I'm trying to run a search that alerts me when 40 accounts is created within 1 minute. I'm talking about linux users.
I've tried this search:
index=XXX process=useradd | stats count by user earliest:-1m@m | where count > 40
But I don't know it's correct.
index=xxx process=useradd earliest=-1m@m | stats count by user | where count>=40
Try like this (the timerange identifier earliest should be in base search)
index=XXX process=useradd earliest=-1m@m latest=@m | stats dc(user) as user_created | where user_created > 40