# Need help for create Opensearch correlation rule for detect brute force attack

**URL:** https://forum.opensearch.org/t/need-help-for-create-opensearch-correlation-rule-for-detect-brute-force-attack/23830
**Category:** Security Analytics
**Created:** [March 19, 2025, 7:35am UTC](https://forum.opensearch.org/t/need-help-for-create-opensearch-correlation-rule-for-detect-brute-force-attack/23830 "2025-03-19T07:35:09Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![sohil2306](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@sohil2306](https://forum.opensearch.org/u/sohil2306)
#### Post date: [March 19, 2025, 7:35am UTC](https://forum.opensearch.org/t/need-help-for-create-opensearch-correlation-rule-for-detect-brute-force-attack/23830/1 "2025-03-19T07:35:09Z")

</div>

Hello everyone,

I am new to OpenSearch and currently exploring OpenSearch Security Analytics. I recently learned that correlation rules can be used to detect specific event scenarios. I would like to create a correlation rule to detect brute force attacks, but I am unable to find proper guidance or documentation on this topic.

Any assistance would be greatly appreciated.

Thank you.

---

<div class="post-metadata">

### Author: ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)
#### Post date: [March 28, 2025, 2:54pm UTC](https://forum.opensearch.org/t/need-help-for-create-opensearch-correlation-rule-for-detect-brute-force-attack/23830/2 "2025-03-28T14:54:22Z")

</div>

Hi @sohil2306,

You can check this sample:

```auto
POST _plugins/_security_analytics/correlation/rules
{
  "name": "Brute Force Detection",
  "enabled": true,
  "description": "Detects multiple failed login attempts from the same IP within a short time",
  "log_sources": [
    {
      "index": "security-logs-*",
      "rule": {
        "name": "failed_login",
        "query": {
          "bool": {
            "must": [
              { "match": { "event.action": "failed_login" } }
            ]
          }
        }
      }
    }
  ],
  "correlation_conditions": [
    {
      "group_by": ["source.ip"],
      "time_window": "5m",
      "aggregation": {
        "count": {
          "field": "event.action",
          "value": 10
        }
      }
    }
  ],
  "severity": "high",
  "risk_score": 80
}

```

Best,  
mj

---

<div class="post-metadata">

### Author: ![sohil2306](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@sohil2306](https://forum.opensearch.org/u/sohil2306)
#### Post date: [March 31, 2025, 7:10am UTC](https://forum.opensearch.org/t/need-help-for-create-opensearch-correlation-rule-for-detect-brute-force-attack/23830/3 "2025-03-31T07:10:36Z")

</div>

I have pasted this code in my dev tool and it has created correlation rule but when i created my index with name “security-logs-cloudwatch” and paste some dummy data but still it is not creating correlation graph.

here is the data which i have filled in my index.  
POST security-logs-cloudwatch/\_bulk  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:00:00Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:00:30Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:01:00Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:01:30Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:02:00Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:02:30Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:02:40Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:02:50Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:02:55Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }  
{ “index”: {} }  
{ “@timestamp”: “2025-03-31T12:02:56Z”, “event.action”: “failed\_login”, “source.ip”: “192.168.1.100”, “user.name”: “admin”, “message”: “Failed login attempt detected” }

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/3/33547ea01a5b12dcca2958411d3edd97ae2ea8c1.png) [@system](https://forum.opensearch.org/u/system)
#### Post date: [May 30, 2025, 7:11am UTC](https://forum.opensearch.org/t/need-help-for-create-opensearch-correlation-rule-for-detect-brute-force-attack/23830/4 "2025-05-30T07:11:06Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
