# Config check, filtering out users

**URL:** <https://discuss.elastic.co/t/config-check-filtering-out-users/279915>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 28, 2021, 9:15pm UTC](https://discuss.elastic.co/t/config-check-filtering-out-users/279915 "2021-07-28T21:15:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sancla](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sancla](https://discuss.elastic.co/u/sancla)\
**Post date:** [July 28, 2021, 9:15pm UTC](https://discuss.elastic.co/t/config-check-filtering-out-users/279915/1 "2021-07-28T21:15:45Z")

</div>

Hey guys,

I'm a bit new to elastic so I can hope a 'specialist' can help me out here.  
I am trying to filter out some security log records from our Exchange servers and it does not seem to be working. The config is tested and it seems to be okay.

I am trying to filter as much as possible on the client side to make the forwarding of events to the elastic cluster efficient. We currently do not have logstash implemented.  
As far as I know, this is currently not a requirement as winlogbeat already sends it in the correct format to the cluster.

Can you help me out and point me in the right direction?  
Any input is appreciated!

winlogbeat.yml:

```auto
...
  - name: Security
    ignore_older: 24h
    event_id: 1100, 1102, 4624, 4625, 4634, 4648, 4657, 4697, 4700-4800, 4946, 4947, 4950, 5025
    processors:
      - drop_event.when.and:
        - equals.event_id: 4634
        - contains.event_data.TargetUserName: HealthMailbox* # Drop Exchange HealthMailbox* logons
      - drop_event.when.and:
        - equals.event_id: 4624
        - contains.event_data.TargetUserName: HealthMailbox* # Drop Exchange HealthMailbox* logons
      - drop_event.when.and:
        - equals.event_id: 4625
        - contains.event_data.TargetUserName: HealthMailbox* # Drop Exchange HealthMailbox* logons
      - drop_event.when.and:
        - equals.event_id: 4624
        - contains.event_data.TargetUserName: "${COMPUTERNAME}$" # Drop local logons (such as EXCHANGE01$)
      - drop_event.when.and:
        - equals.event_id: 4625
        - contains.event_data.TargetUserName: "${COMPUTERNAME}$" # Drop local logons (such as EXCHANGE01$)
      - drop_event.when.and:
        - equals.event_id: 4672
        - contains.event_data.TargetUserName: "${COMPUTERNAME}$" # Drop local logons (such as EXCHANGE01$)
      - drop_event.when.and:
        - equals.event_id: 4624
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js
...

```

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [July 29, 2021, 12:12am UTC](https://discuss.elastic.co/t/config-check-filtering-out-users/279915/2 "2021-07-29T00:12:05Z")

</div>

It should be `winlog.event_id` and `winlog.event_data`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2021, 2:12am UTC](https://discuss.elastic.co/t/config-check-filtering-out-users/279915/3 "2021-08-26T02:12:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
