I'm not completely sure but there are two things I can see here:
When you don't group the values inside a bracket the query becomes something like winlog.event_id: "10002" OR "1003" OR "1234" and the field name winlog.event_id does not apply to "1003" and "1234"
secondly when you quote the value its treated as a string and not number.
I use the format I suggested because this is the kind of format I see being used in the default detection rules.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.