Solved it.
I separated the detection of unknown user ID and unknown login IP. Two rules with everything the same, one looking for userID not in list. The other for user IP not in the list. Both work!!