# 4624 log stoms

**URL:** <https://discuss.elastic.co/t/4624-log-stoms/195684>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [August 19, 2019, 7:12am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684 "2019-08-19T07:12:07Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![james\_007](https://avatars.discourse-cdn.com/v4/letter/j/34f0e0/32.png) [@james\_007](https://discuss.elastic.co/u/james_007)\
**Post date:** [August 19, 2019, 7:12am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/1 "2019-08-19T07:12:07Z")

</div>

Hi All - was wondering if anyone can help on the following:

event ID 4624 : this event logs everything that speaks to the domain, I just want to log user who below to the DD1 domain and forget and drop the rest of the events

below is an event of computer generated 4624 ID, this is the message part of the log

New Logon:

- Security ID: S-1-5-21-3697968490-2924621232-2642631XXXXXXXXX
- Account Name: Servername$ - ( SERVER NAMES)
- Account Domain: ADD - (AD domain Name)
- Logon ID: 0x759ADBE
- Logon GUID: {9DF982D6-118E-2412-9006-XXXXXXXXXXX}

Here is 4624 login from a user that i want to see

New Logon:

- Security ID: S-1-5-21-3697968490-2924621232-XXXXXXXXXXXXXXX
- Account Name: user\_name - (Active Directory USER NAMES)
- Account Domain: FFE – (AD domain Name)
- Logon ID: 0xF7E3345
- Logon GUID: {50DAB2F7-6378-39AA-9DA1-XXXXXXXXXXXXXX}

Is there anyway I can block account names when they are Server names, or for starters block all Account domain that are ADD and accept all domains that are FFE

Or is there another way of doing this ?

thanks

---

<div class="post-metadata">

**Author:** ![james\_007](https://avatars.discourse-cdn.com/v4/letter/j/34f0e0/32.png) [@james\_007](https://discuss.elastic.co/u/james_007)\
**Post date:** [August 19, 2019, 8:44am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/2 "2019-08-19T08:44:25Z")

</div>

I found this post [Dropping logon events for computer accounts not working](https://discuss.elastic.co/t/dropping-logon-events-for-computer-accounts-not-working/190061)  
where i says you should add the following lines

- name: Security  
processors:
  - drop\_event:  
when:  
and:  
- equals:  
event.code: 4624  
- regexp:  
winlog.event\_data.TargetUserName: '.\*$'

however i can't get it to work in my file listed below

* * *

winlogbeat.event\_logs:

- name: Application  
ignore\_older: 72h

- name: System  
event\_id: 104,102,1102,4719,6005,7022,7023,7024,7025,7026,7031,7032,7034,7045,4697,7022,7023,104,6

- name: Security  
event\_id: 4740,4728,4732,4756,4735,4724,4625,4648,1102,4624,5038,6281,4767  
processors:

- drop\_event:  
when:  
and:  
- equals:  
event.code: 4624  
- regexp:  
winlog.event\_data.TargetUserName: '.\*$'

- name: Microsoft-Windows-Sysmon/Operational

- name: Windows PowerShell

- name: Microsoft-Windows-Sysmon/Operational

- name: Microsoft-Windows-PowerShell/Operational

* * *

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [August 19, 2019, 9:02am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/3 "2019-08-19T09:02:56Z")

</div>

> [@james\_007](#):
>
> event.code: 4624
> 
> - regexp:

Hi James,  
Is your indentation correct? yaml are very tricky  
Try inserting two spaces here

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e3b8e88fda8b6cc4bf0d9c48de196cb2e6f6068.png)

---

<div class="post-metadata">

**Author:** ![james\_007](https://avatars.discourse-cdn.com/v4/letter/j/34f0e0/32.png) [@james\_007](https://discuss.elastic.co/u/james_007)\
**Post date:** [August 19, 2019, 9:50am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/4 "2019-08-19T09:50:17Z")

</div>

Hi Ana - thanks for the quick reply

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e0af0aeb50f07b1a98c2e4b1a04f7e7de240818.png)

this is my spacing, you are correct, the ymls are well tricky when it comes to spaces - still not working, spaces are still incorrect ? This is view in text pad, any pointers as my database is filling up with unwanted 4624 events ?

thanks again

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [August 19, 2019, 10:12am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/5 "2019-08-19T10:12:57Z")

</div>

Hi James  
I'm not shure about the sintax you are using...  
Which version of winlogbeats do you have? seems like mixing syntax from different versions.,  
What does this line means?  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b25334d1819e36e76b91c37a2578a0c15c9ba11e.png)  
Here is my working config.  
I drop events 4624, 4634 and 4672 when username start with $ or is a DWM-x or is SYSTEM and drop events 4674,4985,4778,4779,4647,...4766 (because I'll analyze those events later)

```
  - name: Security
    processors:
      - drop_event:
          when:
            and:
              - equals:
                  event.code: 4624
              - or:
                 - regexp:
                    winlog.event_data.TargetUserName: '.*\$' 
                 - regexp:
                    winlog.event_data.TargetUserName: 'DWM\-[0-9]' 
                 - equals:
                    winlog.event_data.TargetUserName: 'SYSTEM'                    
      - drop_event:
          when:
            and:
              - equals:
                  event.code: 4634
              - or:
                 - regexp:
                    winlog.event_data.TargetUserName: '.*\$' 
                 - regexp:
                    winlog.event_data.TargetUserName: 'DWM\-[0-9]' 
                 - equals:
                    winlog.event_data.TargetUserName: 'SYSTEM'                    

      - drop_event:
          when:
            and:
              - equals:
                  event.code: 4672
              - or:
                 - regexp:
                    winlog.event_data.SubjectUserName: '.*\$' 
                 - regexp:
                    winlog.event_data.SubjectUserName: 'DWM\-[0-9]' 
                 - equals:
                    winlog.event_data.SubjectUserName: 'SYSTEM'                     
      - drop_event:
          when:
            and:
              - equals:
                  event.code: 4724
              - not:
                  has_fields: ['winlog.event_data.TargetUserName'] 
                 
## To analize later
      - drop_event:
          when:
            or:
              - equals:
                  event.code: 4674
              - equals:
                  event.code: 4985
              - equals:
                  event.code: 4778
              - equals:
                  event.code: 4779
              - equals:
                  event.code: 4647
              - equals:
                  event.code: 4800
              - equals:
                  event.code: 4801
              - equals:
                  event.code: 4802
              - equals:
                  event.code: 4803
              - equals:
                  event.code: 5378
              - equals:
                  event.code: 5632
              - equals:
                  event.code: 5633
              - equals:
                  event.code: 4765
              - equals:
                  event.code: 4766                  

      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

```

Regards  
Ana

---

<div class="post-metadata">

**Author:** ![james\_007](https://avatars.discourse-cdn.com/v4/letter/j/34f0e0/32.png) [@james\_007](https://discuss.elastic.co/u/james_007)\
**Post date:** [August 19, 2019, 12:16pm UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/6 "2019-08-19T12:16:44Z")

</div>

Thanks Ana - i am using winlogbeats 7.0.3 - the line you are asking about tells winlogbeat what events IDs to sent

- name: Security  
event\_id: 4740,4728,4732,4756,4735,4724,4625,4648,1102,4624,5038,6281,4767

this is my yml file which works, it sends the correct event IDs, i just want insert your code under -name:security but can't seem to get rights.

even our more fancy new code does not work

sorry about all the questions

James

#======================= Winlogbeat specific options ===========================

# [https://go.es.io/WinlogbeatConfig](https://go.es.io/WinlogbeatConfig)

winlogbeat.event\_logs:

- name: Application  
ignore\_older: 72h

- name: System  
event\_id: 104,102,1102,4719,6005,7022,7023,7024,7025,7026,7031,7032,7034,7045,4697,7022,7023,104,6

- name: Security  
event\_id: 4740,4728,4732,4756,4735,4724,4625,4648,1102,4624,5038,6281,4767

- name: Microsoft-Windows-Sysmon/Operational

- name: Windows PowerShell

- name: Microsoft-Windows-Sysmon/Operational

- name: Microsoft-Windows-PowerShell/Operational

#==================== Elasticsearch template settings ==========================

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [August 19, 2019, 12:47pm UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/7 "2019-08-19T12:47:11Z")

</div>

Hi James  
I'll test your config and I'll let you know if I succeed 😊  
Regards  
Ana

---

<div class="post-metadata">

**Author:** ![james\_007](https://avatars.discourse-cdn.com/v4/letter/j/34f0e0/32.png) [@james\_007](https://discuss.elastic.co/u/james_007)\
**Post date:** [August 19, 2019, 12:58pm UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/8 "2019-08-19T12:58:32Z")

</div>

nice one -

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [August 20, 2019, 11:24am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/9 "2019-08-20T11:24:15Z")

</div>

Hi @james_007 ,  
I have tested what you want to do and it works.  
I've configure winlogbeat to _ **send only events 4624 and 4672** _ and drop the events 4624 under certain conditions. For testing I _ **drop the event 4624 for user at\_adm** _

Here is the config

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/5/65b1c8a22f62071e5b224d760a7394f51f5683e6.png)

And here the results.... no event 4624 for user at\_adm

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5fc7e189d0f18fcf833fe36e55e0dee324f9f0ad.jpeg)

Regards  
Ana

---

<div class="post-metadata">

**Author:** ![james\_007](https://avatars.discourse-cdn.com/v4/letter/j/34f0e0/32.png) [@james\_007](https://discuss.elastic.co/u/james_007)\
**Post date:** [September 11, 2019, 10:32am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/10 "2019-09-11T10:32:02Z")

</div>

Hi Ana - many thanks for your reply i shall copy your code and see if it works, fingers crossed.

sorry for the late reply, off for holidays.

007

---

<div class="post-metadata">

**Author:** ![james\_007](https://avatars.discourse-cdn.com/v4/letter/j/34f0e0/32.png) [@james\_007](https://discuss.elastic.co/u/james_007)\
**Post date:** [September 13, 2019, 8:00am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/11 "2019-09-13T08:00:16Z")

</div>

Hi Ana - silly question, is the DWM your domain name ?

thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2019, 8:00am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/12 "2019-10-11T08:00:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
