Filter events by source using REGEXP

Hello, I'm working on a winlogbeat.yml. I want to filter event by events providers. I am using the REGEXP property so that all the events that would not begin as specified , would just be dropped.
I'm so new to ELK.
Here is what i tried basing on the Regexp definition. But I'm not getting anything (zero event) on the output.

       - name: Application
            - drop_event.when.not.regexp.winlog.provider_name: "^Configuration.*"
            - drop_event.when.not.regexp.winlog.provider_name: "^Cisco.*"

This means that I'm supposed to get all the events beginning by "Configuration" or "Cisco"
Here is a link to documentation
I wish I could get some help here.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.