# Combining processors for Graylog

**URL:** <https://discuss.elastic.co/t/combining-processors-for-graylog/192437>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 26, 2019, 12:35pm UTC](https://discuss.elastic.co/t/combining-processors-for-graylog/192437 "2019-07-26T12:35:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdobson90](https://avatars.discourse-cdn.com/v4/letter/m/ebca7d/32.png) [@mdobson90](https://discuss.elastic.co/u/mdobson90)\
**Post date:** [July 26, 2019, 12:35pm UTC](https://discuss.elastic.co/t/combining-processors-for-graylog/192437/1 "2019-07-26T12:35:06Z")

</div>

Hi all,

Total noob here with Elastic, so hopefully you can help.  
I'm running a Graylog server which uses elastic backend, and have winlogbeat installed on all PCs via the Graylog Collector Sidecar.

My current config is:

winlogbeat.event\_logs:

- name: System  
level: critical, error, warning
- name: Security  
level: critical, error, warning
- name: Application  
level: critical, error, warning

This works fine.

I'm looking to be able to also capture SOME informational event IDs, such as account logons/logoffs.  
In order to do this, I want to effectively say:

winlogbeat.event\_logs:

- name: System  
level: critical, error, warning
- name: Security  
level: critical, error, warning  
**AND event ID's 4264 and 4634**
- name: Application  
level: critical, error, warning

Is this possible?

Thanks,

Matt Dobson

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2019, 12:35pm UTC](https://discuss.elastic.co/t/combining-processors-for-graylog/192437/2 "2019-08-23T12:35:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
