# 4624 log stoms

**URL:** <https://discuss.elastic.co/t/4624-log-stoms/195684>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [August 19, 2019, 7:12am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684 "2019-08-19T07:12:07Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![james\_007](https://avatars.discourse-cdn.com/v4/letter/j/34f0e0/32.png) [@james\_007](https://discuss.elastic.co/u/james_007)\
**Post date:** [August 19, 2019, 8:44am UTC](https://discuss.elastic.co/t/4624-log-stoms/195684/2 "2019-08-19T08:44:25Z")

</div>

I found this post [Dropping logon events for computer accounts not working](https://discuss.elastic.co/t/dropping-logon-events-for-computer-accounts-not-working/190061)  
where i says you should add the following lines

- name: Security  
processors:
  - drop\_event:  
when:  
and:  
- equals:  
event.code: 4624  
- regexp:  
winlog.event\_data.TargetUserName: '.\*$'

however i can't get it to work in my file listed below

* * *

winlogbeat.event\_logs:

- name: Application  
ignore\_older: 72h

- name: System  
event\_id: 104,102,1102,4719,6005,7022,7023,7024,7025,7026,7031,7032,7034,7045,4697,7022,7023,104,6

- name: Security  
event\_id: 4740,4728,4732,4756,4735,4724,4625,4648,1102,4624,5038,6281,4767  
processors:

- drop\_event:  
when:  
and:  
- equals:  
event.code: 4624  
- regexp:  
winlog.event\_data.TargetUserName: '.\*$'

- name: Microsoft-Windows-Sysmon/Operational

- name: Windows PowerShell

- name: Microsoft-Windows-Sysmon/Operational

- name: Microsoft-Windows-PowerShell/Operational

* * *

---

_[View the full topic](https://discuss.elastic.co/t/4624-log-stoms/195684)._
