Droping winlog.event_data.LogonType: "3"

Hey @kubekpk,

I think the condition for event_id should be equals.winlog.event_id: 4624, as the event_id field is under a winlog object.

You can take a look to this topic, where a similar configuration is discussed: Filter system logons