# Droping winlog.event\_data.LogonType: "3"

**URL:** <https://discuss.elastic.co/t/droping-winlog-event-data-logontype-3/231883>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 10, 2020, 11:09am UTC](https://discuss.elastic.co/t/droping-winlog-event-data-logontype-3/231883 "2020-05-10T11:09:06Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [May 10, 2020, 12:42pm UTC](https://discuss.elastic.co/t/droping-winlog-event-data-logontype-3/231883/2 "2020-05-10T12:42:09Z")

</div>

Hey @kubekpk,

I think the condition for `event_id` should be `equals.winlog.event_id: 4624`, as the `event_id` field is under a `winlog` object.

You can take a look to this topic, where a similar configuration is discussed: [Filter system logons](https://discuss.elastic.co/t/filter-system-logons/225001)

---

_[View the full topic](https://discuss.elastic.co/t/droping-winlog-event-data-logontype-3/231883)._
