So what I'm attempting to do, is I have a list of user, IP, city, state, country, time.
I want to alert if I see a user on two different IP's within a 5-15? minute (short period of time) interval.
Any suggestions?
Perhaps this will help. Run it once per minute.
index=foo earliest=-5m | stats count, values(*) as * by user | where count > 1