# Dropping Events using Winlogbeat Processors

**URL:** <https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 3, 2018, 12:24am UTC](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781 "2018-10-03T00:24:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![popa](https://avatars.discourse-cdn.com/v4/letter/p/dec6dc/32.png) [@popa](https://discuss.elastic.co/u/popa)\
**Post date:** [October 3, 2018, 12:24am UTC](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781/1 "2018-10-03T00:24:10Z")

</div>

Good morning!

I've done some reading in Winlogbeat's documentation and wanted to confirm the syntax of a processor that I'm trying to implement.

I have a noisy event that I want to drop before it makes it to Logstash --\> Elasticsearch --\> Kibana. Here's the query I use in Kibana to pull the events:

- `event_data.ProcessName: "*Scan64.Exe" AND event_id: "4656"`

- `event_data.ProcessName: "*mcshield.exe" AND event_id: "4663"`

I believe the structure of the processor should look something like this:

```auto
processors:
- drop_event:
    when:
       equals:
           event_data.ProcessName: ["Scan64.Exe"]
       equals:
           event_id: ["4656"]

```

and

```auto
processors:
- drop_event:
    when:
       equals:
           event_data.ProcessName: ["mcshield.exe"]
       equals:
           event_id: ["4663"]

```

Does this look like the correct syntax to drop both of the conditions that I described above?

Thank you in advance for your help!

---

<div class="post-metadata">

**Author:** ![popa](https://avatars.discourse-cdn.com/v4/letter/p/dec6dc/32.png) [@popa](https://discuss.elastic.co/u/popa)\
**Post date:** [October 3, 2018, 2:15am UTC](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781/2 "2018-10-03T02:15:36Z")

</div>

Currently testing out the following and will update this post if it works:

```auto
processors:
- drop_event.when.and:
    - equals.event_data.ProcessName: 'mcshield.exe'
    - equals.event_id: '4663'
- drop_event.when.and:
    - equals.event_data.ProcessName: 'Scan64.Exe'
    - equals.event_id: '4656'

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 3, 2018, 8:37pm UTC](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781/3 "2018-10-03T20:37:45Z")

</div>

Your last post looks like it uses the correct syntax.

---

<div class="post-metadata">

**Author:** ![popa](https://avatars.discourse-cdn.com/v4/letter/p/dec6dc/32.png) [@popa](https://discuss.elastic.co/u/popa)\
**Post date:** [October 4, 2018, 7:14am UTC](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781/4 "2018-10-04T07:14:21Z")

</div>

Implemented the change, however, it's not dropping the events. Here's what I have:

```auto
processors:
- drop_event.when.and:
  - equals.event_data.ProcessName: 'C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe'
  - equals.event_id: '4663'
- drop_event.when.and:
  - equals.event_data.ProcessName: 'C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\Scan64.Exe'
  - equals.event_id: '4656'
- drop_event.when.and:
  - equals.event_data.ProcessName: 'C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\Scan64.Exe'
  - equals.event_id: '4689'

```

Ideally this will drop any event that matches the following queries:

```auto
(event_data.ProcessName: "C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe" and event_id: "4663")
(event_data.ProcessName: "C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\Scan64.Exe" and event_id: "4656")
(event_data.ProcessName: "C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\Scan64.Exe" and event_id: "4689")

```

Are there any issues with using `' '` versus using `" "` when using Windows paths?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 4, 2018, 1:43pm UTC](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781/5 "2018-10-04T13:43:21Z")

</div>

How about trying with `equals.event_id: 4689` (no quotes, where the event\_id is a number rather than a string)?

---

<div class="post-metadata">

**Author:** ![popa](https://avatars.discourse-cdn.com/v4/letter/p/dec6dc/32.png) [@popa](https://discuss.elastic.co/u/popa)\
**Post date:** [October 5, 2018, 1:07am UTC](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781/6 "2018-10-05T01:07:43Z")

</div>

Looks like it works so far, @andrewkroh. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2018, 1:07am UTC](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781/7 "2018-11-02T01:07:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
