# Droping events based on ip adr from sysmon

**URL:** <https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 7, 2018, 2:00pm UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734 "2018-11-07T14:00:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssi](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@ssi](https://discuss.elastic.co/u/ssi)\
**Post date:** [November 7, 2018, 2:00pm UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/1 "2018-11-07T14:00:08Z")

</div>

hi i believe this is close to what im seeing, at least im trying the same thing and not getting any success.

> [@Dropping Events using Winlogbeat Processors](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781):
>
> Good morning! I've done some reading in Winlogbeat's documentation and wanted to confirm the syntax of a processor that I'm trying to implement. I have a noisy event that I want to drop before it makes it to Logstash --\> Elasticsearch --\> Kibana. Here's the query I use in Kibana to pull the events: event\_data.ProcessName: "\*Scan64.Exe" AND event\_id: "4656" event\_data.ProcessName: "\*mcshield.exe" AND event\_id: "4663" I believe the structure of the processor should look something like t…

the sysmon is being send from a windows event collector with a winlogbeat agent on to logstash

here is the winlogbeat conf.

###################### Winlogbeat Configuration Example ##########################

# This file is an example configuration file highlighting only the most common

# options. The winlogbeat.reference.yml file from the same directory contains all the

# supported options with more comments. You can use it as a reference.

# 

# You can find the full configuration reference here:

# [Winlogbeat Reference | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/index.html)

#======================= Winlogbeat specific options ==========================

# event\_logs specifies a list of event logs to monitor as well as any

# accompanying options. The YAML data type of event\_logs is a list of

# dictionaries.

# 

# The supported keys are name (required), tags, fields, fields\_under\_root,

# forwarded, ignore\_older, level, event\_id, provider, and include\_xml. Please

# visit the documentation for the complete details of each option.

# [Configure Winlogbeat | Beats](https://go.es.io/WinlogbeatConfig)

winlogbeat.event\_logs:

- name: ForwardedEvents  
ignore\_older: 12h  
event\_logs.forwarded: false  
#--------processors-------------  
processors:

the bullets are actualley a "-"

- drop\_event.when.or:
  - equals.event\_data.DestinationIp: ["40.101.51.226", "40.101.51.130","52.114.32.7","13.107.2.0/22", "20.36.64.0/19", "204.79.197.213", "20.36.112.0/21", "40.82.12.0/22", "40.82.244.0/22", "40.90.130.32/28", "40.90.142.64/27", "40.90.149.32/27", "40.126.128.0/18", "52.143.218.0/24", "52.239.218.0/23", "20.36.32.0/19", "20.36.104.0/21", "20.37.0.0/18", "40.82.8.0/22", "40.82.240.0/22", "40.90.130.48/28", "40.90.142.96/27", "40.90.149.64/27", "52.143.219.0/24", "52.239.216.0/23", "13.70.64.0/18", "13.72.224.0/19", "13.73.192.0/20", "13.75.128.0/17", "20.37.192.0/19", "20.188.128.0/17", "20.190.142.0/25", "20.191.192.0/18", "23.101.208.0/20", "40.79.160.0/20", "40.79.211.0/24", "40.82.32.0/22", "40.82.192.0/19", "40.87.208.0/22", "40.90.130.80/28", "40.90.130.208/28", "40.90.140.32/27", "40.90.142.160/27", "40.90.147.64/27", "40.90.150.0/27", "40.112.37.128/26", "40.126.14.0/25", "40.126.224.0/19", "52.108.40.0/23", "52.109.112.0/22", "52.114.16.0/22", "52.147.0.0/19", "52.156.160.0/19", "52.187.192.0/18", "52.232.136.0/21", "52.232.154.0/24", "52.237.192.0/18", "52.239.130.0/23", "52.239.226.0/24", "52.245.16.0/22", "104.44.90.64/26", "104.44.93.96/27", "104.44.95.48/28", "104.46.29.0/24", "104.46.30.0/23", "104.46.240.0/20", "104.209.80.0/20", "104.210.64.0/18", "191.238.66.0/23", "191.239.64.0/19", "13.70.128.0/18", "13.73.96.0/19", "13.77.0.0/18", "20.190.96.0/19", "20.190.142.128/25", "23.101.224.0/19", "40.79.212.0/24", "40.81.48.0/20", "40.87.212.0/22", "40.90.138.128/27", "40.112.37.192/26", "40.115.64.0/19", "40.117.0.0/19", "40.126.14.128/25", "40.127.64.0/19", "52.108.234.0/23", "52.109.116.0/22", "52.114.20.0/22", "52.136.25.0/24", "52.147.32.0/19", "52.158.128.0/19", "52.189.192.0/18", "52.239.132.0/23", "52.239.225.0/24", "52.243.64.0/18", "52.245.20.0/22", "52.255.32.0/19", "104.44.90.32/27", "104.44.93.128/27", "104.44.95.64/28", "104.46.28.0/24", "104.209.64.0/20", "191.239.160.0/19", "191.239.192.0/22", "20.190.145.0/25", "23.97.96.0/19", "40.90.133.32/27", "40.90.141.64/27", "40.90.144.224/27", "40.126.17.0/25", "52.108.36.0/22", "52.109.108.0/22", "104.41.0.0/18", "191.232.32.0/19", "191.232.160.0/19", "191.232.192.0/18", "191.233.0.0/21", "191.233.24.0/21", "191.233.128.0/24", "191.233.130.0/23", "191.233.132.0/22", "191.233.136.0/21", "191.233.192.0/18", "191.234.160.0/19", "191.235.32.0/19", "191.235.64.0/18", "191.235.196.0/22", "191.235.200.0/21", "191.235.224.0/20", "191.235.240.0/21", "191.237.195.0/24", "191.237.200.0/21", "191.237.248.0/21", "191.238.128.0/21", "191.238.192.0/19", "191.239.112.0/20", "191.239.204.0/22", "191.239.240.0/20", "13.71.160.0/19", "13.88.224.0/19"]

based on what i can see in the initial mentioned topic i can get winlogbeat to drop a given event id here this would be event id 3.

is it possible to get winlogbeat to drop the event if event id 3 contains one of the ip adresses mentioned above?

an alternative i guess would be to do this in logstash, but if i can get the noise filtered out before i hit logstash i would prefer this.

---

<div class="post-metadata">

**Author:** ![ssi](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@ssi](https://discuss.elastic.co/u/ssi)\
**Post date:** [November 8, 2018, 9:35am UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/2 "2018-11-08T09:35:07Z")

</div>

hi again i have tried to recreate this advise from a privious post

> [@Winlogbeat and drop\_event filter](https://discuss.elastic.co/t/winlogbeat-and-drop-event-filter/81990):
>
> Hello all, I've configured winlogbeat to collect events from one of our domain controllers, there is a particular service account that generates thousands of successful authentication events each day and we're not interested in collecting those events. I therefore tried to create a filter that would drop those event IDs with that particular account as the target username (we'll call the account 'test-user' in this example). Here is the processor filter I added to the winlogbeat.yml file: proces…

`

```
processors:
- drop_event:
      when:
      and:
      - or:
        - equals.event_id: 3
      - equals.event_data.DestinationIp: ["40.101.48.82", "40.101.65.130", "52.178.207.179", "52.114.32.8", "40.101.50.2", "13.107.18.11", "40.101.51.194", "52.114.76.34"]

```

/\>  
but i still get the ip adresses sent to logstash?

disreguard the formatting when i c/p from the yml file it ends up like this, but am i on the right track here ?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 8, 2018, 2:45pm UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/3 "2018-11-08T14:45:44Z")

</div>

Could you please format your configuration using `</>`?

---

<div class="post-metadata">

**Author:** ![ssi](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@ssi](https://discuss.elastic.co/u/ssi)\
**Post date:** [November 8, 2018, 3:24pm UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/4 "2018-11-08T15:24:35Z")

</div>

sorry fixed now

---

<div class="post-metadata">

**Author:** ![ssi](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@ssi](https://discuss.elastic.co/u/ssi)\
**Post date:** [November 8, 2018, 3:31pm UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/5 "2018-11-08T15:31:00Z")

</div>

this from a sysmon event id 3

original message looks like this

Network connection detected:  
UtcTime: 2018-11-08 15:24:06.245  
ProcessGuid: {04A01A50-95E3-5BE1-0000-00105E104800}  
ProcessId: 11240  
Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE  
User: XXX\XXXX  
Protocol: tcp  
Initiated: true  
SourceIsIpv6: false  
SourceIp: 172.x.xx.x.x  
SourceHostname: PCbalbal  
SourcePort: 65411  
SourcePortName:  
DestinationIsIpv6: false  
DestinationIp: 40.101.48.82  
DestinationHostname:  
DestinationPort: 443  
DestinationPortName: https

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 8, 2018, 3:48pm UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/6 "2018-11-08T15:48:24Z")

</div>

> [@ssi](#):
>
> is it possible to get winlogbeat to drop the event if event id 3 contains one of the ip adresses mentioned above?

It is possible. But in your original post you used CIDR ranges and Beats do not have support for matching CIDR ranges so you would have to use exact IP addresses or a regular expression.

So if the logic you want is drop\_event when `(event_id == 3) AND (event_data.DestinationIp == "40.101.48.82" OR event_data.DestinationIp == "40.101.65.130")` then this should work:

```auto
processors:
- drop_event:
    when:
      and:
        - equals.event_id: 3
        - or:
            - equals.event_data.DestinationIp: '40.101.48.82'
            - equals.event_data.DestinationIp: '40.101.65.130'

```

Indentation is critical in YAML.

[http://www.yamllint.com/](http://www.yamllint.com/) is your friend and can be used to check that your YAML is valid.

---

<div class="post-metadata">

**Author:** ![ssi](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@ssi](https://discuss.elastic.co/u/ssi)\
**Post date:** [November 8, 2018, 4:22pm UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/7 "2018-11-08T16:22:06Z")

</div>

hi thanks

this means i have to make a line for each ip adr i want to drop then?

its not possible to list the DestinatioIP that i want to drop like

...  
- or:  
- equals.event\_data.DestionationIp: ['40.101.48.82', '40.101.65.130']

i think that is what you are getting at, just wanted to be sure 😉

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 9, 2018, 12:32am UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/8 "2018-11-09T00:32:05Z")

</div>

That's correct. The `equals` condition does not currently have support for a string array value. It has support for int, string, and bool. You can see the source code [here](https://github.com/elastic/beats/blob/81fa63625fc39f93f625fc65227e089e1d0a2bcf/libbeat/conditions/equals.go#L40-L56)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2018, 12:32am UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/9 "2018-12-07T00:32:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
