Forgive me if I've missed this in the docs as I couldn't see it.
Is it possible to drop an entire log based on a condition?
i.e. eventlog_id 5156 is never needed and is disabled on the majority of servers we have. Rather than output these to elasticsearch can any WindowsEventLog types with the eventlog_id field = 5156 just be ignored rather than outputting to elasticsearch?