@johann2017 so you want to count by account name, irrespective of the source/target host, so this should work
| eval Login=src_ip."-->".host
| stats values(Login) as Logins count as Total by Account_Name
| where Total > 9
This is then generating a new field with the source/target pair called 'Login' and then counting all pairs by the account name and filtering less=9.
Here's a full example
| makeresults
| rename COMMENT as "Setting up data to show example"
| eval f="Admin1,10.10.16.86,server1#Admin2,10.10.16.87,server2#Admin1,10.10.16.88,server3#Admin2,10.10.16.89,server4#Admin1,10.10.16.90,server5#Admin2,10.10.16.85,server6#Admin1,10.10.16.84,server7#Admin2,10.10.16.83,server8#Admin1,10.10.16.82,server9#Admin2,10.10.16.81,server10#Admin1,10.10.16.80,server11#Admin3,10.10.17.86,server12#Admin1,10.10.18.86,server13#Admin3,10.10.19.86,server14#Admin1,10.10.15.86,server15#Admin3,10.10.14.86,server16"
| makemv delim="#" f
| mvexpand f
| rex field=f "(?<Account_Name>[^,]*),(?<src_ip>[^,]*),(?<host>.*)"
| eval d=15
| accum d
| eval _time=_time+d
| rename COMMENT as "This is what you should do"
| eval Login=src_ip.":".host
| stats values(Login) as Logins count as Total by Account_Name
| where Total > 4
Note here I use (4) to demonstrate, but this will give you a row per user with the values as a multi value field. If you want a row per login then you will have to split back out the values, like
| mvexpand Logins
| eval tmp=split(Logins, ":")
| eval src_ip=mvindex(tmp,0,0)
| eval host=mvindex(tmp,1,1)
| fields Account_Name, src_ip, host, Total
Hope this helps
... View more