# Event filter for Elastict Agent and Endpoint Security

**URL:** <https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429>\
**Category:** SIEM\
**Created:** [July 12, 2022, 2:13pm UTC](https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429 "2022-07-12T14:13:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Axel\_zendata](https://avatars.discourse-cdn.com/v4/letter/a/e79b87/32.png) [@Axel\_zendata](https://discuss.elastic.co/u/Axel_zendata)\
**Post date:** [July 12, 2022, 2:13pm UTC](https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429/1 "2022-07-12T14:13:41Z")

</div>

Dear all,

I created lot of event filter in Security -\> Event Filter for the Elastic Endpoint Agent, but it 's still impossible to use regular expression to exclude event (except for file.path.text).

> **[Event filters | Elastic Security Solution \[8.3\] | Elastic](https://www.elastic.co/guide/en/security/current/event-filters.html)**

Do you have an idea how to create regex event filter for the registry path field (for example)? If you have some example, I'm really interested

Thanks for your help

---

<div class="post-metadata">

**Author:** ![Michael\_Olorunnisola](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_olorunnisola/32/88980_2.png) [@Michael\_Olorunnisola](https://discuss.elastic.co/u/Michael_Olorunnisola)\
**Post date:** [July 12, 2022, 7:10pm UTC](https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429/2 "2022-07-12T19:10:29Z")

</div>

Hi @Axel_zendata ! Thank you for reaching out here. You are correct that the regex wildcards are only available for the file path in the event filters currently. I've spoken with the team that manages this functionality and they plan on adding it to their roadmap as an enhancement to the event filters.

---

<div class="post-metadata">

**Author:** ![Axel\_zendata](https://avatars.discourse-cdn.com/v4/letter/a/e79b87/32.png) [@Axel\_zendata](https://discuss.elastic.co/u/Axel_zendata)\
**Post date:** [July 13, 2022, 5:48am UTC](https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429/3 "2022-07-13T05:48:08Z")

</div>

Hi @Michael_Olorunnisola , Great news, thanks for your answer

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2022, 5:48am UTC](https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429/4 "2022-08-10T05:48:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
