This server is configured to alert when someone logs in, the threshold settings:

Query:
"query_string": {
"query": "(type:\"syslog-nimble\") (host:\"10.<snip>\" OR host:\"10.<snip>\" OR host:\"10.<snip>\") AND (\"Status:Succeeded\" OR \"Status:Failed\") not (object:admin access type:su) not (access type:oauth client ip:127.0.0.1)"
The email method is SMTP to Office365, the host is allowed to relay.
I would appreciate any guidance,
Thanks, in advance.
Joe