# Dropping network events for private IP range through Winlogbeat yml config

**URL:** <https://discuss.elastic.co/t/dropping-network-events-for-private-ip-range-through-winlogbeat-yml-config/269027>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 1, 2021, 11:38am UTC](https://discuss.elastic.co/t/dropping-network-events-for-private-ip-range-through-winlogbeat-yml-config/269027 "2021-04-01T11:38:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Psyhil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/psyhil/32/116080_2.png) [@Psyhil](https://discuss.elastic.co/u/Psyhil)\
**Post date:** [April 1, 2021, 11:38am UTC](https://discuss.elastic.co/t/dropping-network-events-for-private-ip-range-through-winlogbeat-yml-config/269027/1 "2021-04-01T11:38:58Z")

</div>

Hi there,

We are forwarding system network event logs via winlogbeat generated by sysmon and was attempting at dropping internal traffic events using private IP ranges.  
Seems yml config does not supports wildcard hence cannot use \<10.\*\>  
Is there another way in winlogbeat to accomplish this?  
Sysmon conditional grouping rules is another issue hence unable to do that.

Thank you in advance!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 1, 2021, 12:07pm UTC](https://discuss.elastic.co/t/dropping-network-events-for-private-ip-range-through-winlogbeat-yml-config/269027/2 "2021-04-01T12:07:12Z")

</div>

My recommendation is to drop the events as close to the source as possible to avoid storing data you don't care about and avoid processing costs in Winlogbeat. With Sysmon that would be through rules in the sysmon XML config. You can filter network events with a wildcard [Sysmon - Windows Sysinternals | Microsoft Docs](https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon#event-filtering-entries). And here's an example [sysmon-config/sysmonconfig-export.xml at 5ded528c3386c11be1ca0c972035617f412ad0f8 · SwiftOnSecurity/sysmon-config · GitHub](https://github.com/SwiftOnSecurity/sysmon-config/blob/5ded528c3386c11be1ca0c972035617f412ad0f8/sysmonconfig-export.xml#L347-L359).

Winlogbeat can also drop events based on [network CIDR ranges](https://www.elastic.co/guide/en/beats/winlogbeat/current/defining-processors.html#condition-network) or based on regular expressions if you prefer that approach.

```auto
processors:
  - drop_event:
      when:
        network:
          source.ip: private

```

```auto
processors:
  - drop_event:
      when:
        network:
          source.ip: '10.0.0.0/8'

```

---

<div class="post-metadata">

**Author:** ![Psyhil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/psyhil/32/116080_2.png) [@Psyhil](https://discuss.elastic.co/u/Psyhil)\
**Post date:** [April 6, 2021, 1:22pm UTC](https://discuss.elastic.co/t/dropping-network-events-for-private-ip-range-through-winlogbeat-yml-config/269027/3 "2021-04-06T13:22:28Z")

</div>

Thank you Andrew for guiding!  
I was using an old schema for the sysmon xml which did not have capability for group rules with conditions.  
I had tried to use CIDR value in the winlogbeat yml config file which I believe is not supported similar to wildcards.  
Pre processors is something I have noted for future use as have never used them before,not too late to use them 🙂  
Finally updated the Sysmon config to have the conditional rule groups and they are working.

Thank you once again for helping out, I just love being part of this super helpful community.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2021, 3:22pm UTC](https://discuss.elastic.co/t/dropping-network-events-for-private-ip-range-through-winlogbeat-yml-config/269027/4 "2021-05-04T15:22:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
