# Elastic - Event Filtering

**URL:** <https://discuss.elastic.co/t/elastic-event-filtering/363694>\
**Category:** Elastic Security\
**Created:** [July 24, 2024, 10:32am UTC](https://discuss.elastic.co/t/elastic-event-filtering/363694 "2024-07-24T10:32:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [July 24, 2024, 10:32am UTC](https://discuss.elastic.co/t/elastic-event-filtering/363694/1 "2024-07-24T10:32:07Z")

</div>

Hi,

Please assist i have tried to apply event filtering on multiple of process name and applied globally but i'm still seeing the events triggering and i cant apply process names on Trusted Applications due to there's no feature for that.

How does the Event Filtering work or am i doing something wrong?

Harmony

---

<div class="post-metadata">

**Author:** ![Sergi\_Massaneda\_Dona](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergi_massaneda_dona/32/107149_2.png) [@Sergi\_Massaneda\_Dona](https://discuss.elastic.co/u/Sergi_Massaneda_Dona)\
**Post date:** [July 24, 2024, 11:49am UTC](https://discuss.elastic.co/t/elastic-event-filtering/363694/2 "2024-07-24T11:49:15Z")

</div>

Hello @Charles_Nkuna,

Here's the Event Filters documentation:

> **[Event filters | Elastic Security Solution \[8.14\] | Elastic](https://www.elastic.co/guide/en/security/current/event-filters.html)**

If you are unable to resolve the issue, would you be able to share the `process.name` filter settings so we can ensure it is set correctly?

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [July 24, 2024, 1:34pm UTC](https://discuss.elastic.co/t/elastic-event-filtering/363694/3 "2024-07-24T13:34:36Z")

</div>

Hi Sergi,

Based on your document shared i have followed the correct steps.

Please see attached

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e71459923abcc1e1c41049f5827ea7825d12570f.png)

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [July 24, 2024, 4:50pm UTC](https://discuss.elastic.co/t/elastic-event-filtering/363694/4 "2024-07-24T16:50:46Z")

</div>

Hi @Charles_Nkuna

Event filters will cause matching events to not be written to Elasticsearch. but they won't prevent alerts from being generated for any suspicious activity that matches the filter. Event filters are processed on the host not in Elasticsearch so they don't affect prior event documents.

Some things to look at to see why this isn't working for you:

1. Is the event filter being applied to the Endpoint? You've said the filter is global, so just make sure after saving the filter that Agent/Endpoint remains HEALTHY.
2. It can take a few minutes for the filter to apply to the Agent/Endpoint. So don't expect matching activity to be filtered immediately.
3. Is there a casing comparison difference between the filter and the actual event?
4. Are all event filters not working for you or just the `IS ONE OF` filter you shared? Maybe try different filter operators and fields to see if anything does work.

Hopefully those things will help you narrow down what's causing trouble. If not, I can try to replicate your set up. So I can do that, can you let me know what versions of Kibana and Agent you are running and then also DM me a full event that you think should have been filtered (make sure the event was generated after the filter was applied) and also a non-masked screenshot of the event filter that should have suppressed it? (Feel free to a new filter and/or redact the event document you share but just clearly mark which fields you've redacted so I know).

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [July 24, 2024, 6:25pm UTC](https://discuss.elastic.co/t/elastic-event-filtering/363694/5 "2024-07-24T18:25:55Z")

</div>

We have a way to verify this on the target machine. When you generate Agent diagnostics, there's a file `components\endpoint-[guid]\metrics.json`

Example of the relevant section of the json:

```auto
            "documents_volume": {
                "file_events": {
                    "sent_bytes": 215270403,
                    "sent_count": 124413,
                    "suppressed_bytes": 0,
                    "suppressed_count": 0
                },
                "network_events": {
                    "sent_bytes": 86352717,
                    "sent_count": 48202,
                    "suppressed_bytes": 0,
                    "suppressed_count": 0
                },
                "overall": {
                    "sent_bytes": 3482753908,
                    "sent_count": 1366588,
                    "suppressed_bytes": 0,
                    "suppressed_count": 0
                },
                "process_events": {
                    "sent_bytes": 3181130788,
                    "sent_count": 1193973,
                    "suppressed_bytes": 0,
                    "suppressed_count": 0
                }
            },
            "event_filter": {
                "active_global_count": 0,
                "active_user_count": 0
            },

```

All the event filters you've added should be counted by `active_user_count`, if it's 0 then no event filter has been applied on the Endpoint yet. All documents not sent to the stack due to event filter increase relevant `suppressed_count`.

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [July 25, 2024, 5:27am UTC](https://discuss.elastic.co/t/elastic-event-filtering/363694/6 "2024-07-25T05:27:48Z")

</div>

Hi Ferullo

Sent details via DM

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2024, 5:28am UTC](https://discuss.elastic.co/t/elastic-event-filtering/363694/7 "2024-08-22T05:28:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
