# Droping events based on ip adr from sysmon

**URL:** <https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [November 7, 2018, 2:00pm UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734 "2018-11-07T14:00:08Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![ssi](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@ssi](https://discuss.elastic.co/u/ssi)\
**Post date:** [November 8, 2018, 9:35am UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734/2 "2018-11-08T09:35:07Z")

</div>

hi again i have tried to recreate this advise from a privious post

> [@Winlogbeat and drop\_event filter](https://discuss.elastic.co/t/winlogbeat-and-drop-event-filter/81990):
>
> Hello all, I've configured winlogbeat to collect events from one of our domain controllers, there is a particular service account that generates thousands of successful authentication events each day and we're not interested in collecting those events. I therefore tried to create a filter that would drop those event IDs with that particular account as the target username (we'll call the account 'test-user' in this example). Here is the processor filter I added to the winlogbeat.yml file: proces…

`

```
processors:
- drop_event:
      when:
      and:
      - or:
        - equals.event_id: 3
      - equals.event_data.DestinationIp: ["40.101.48.82", "40.101.65.130", "52.178.207.179", "52.114.32.8", "40.101.50.2", "13.107.18.11", "40.101.51.194", "52.114.76.34"]

```

/\>  
but i still get the ip adresses sent to logstash?

disreguard the formatting when i c/p from the yml file it ends up like this, but am i on the right track here ?

---

_[View the full topic](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734)._
