# Filter winlogbeat by eventID

**URL:** <https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770>\
**Category:** Logstash\
**Created:** [April 19, 2018, 9:23pm UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770 "2018-04-19T21:23:01Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![PandKing](https://avatars.discourse-cdn.com/v4/letter/p/258eb7/32.png) [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Post date:** [April 19, 2018, 9:23pm UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770/1 "2018-04-19T21:23:01Z")

</div>

Hi,

I am sending wineventlogs to logstash at about 60k/m and we need to send about 100 matching eventID's to an output.

It would be ugly to add 100 or statements to this filter and just wondering what the best way might be from a management and performance standpoint.

if [type]=="wineventlog" and "DC" in [tags] {

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [April 20, 2018, 2:52am UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770/2 "2018-04-20T02:52:55Z")

</div>

Did you try this in winlogbeat config?  
[https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#\_literal\_event\_logs\_event\_id\_literal](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_literal_event_logs_event_id_literal)  
Enter EventID you need look like 🙂

```
winlogbeat.event_logs:
  - name: Security
    event_id: 4624, 4625, 4700-4800, -4735
```

---

<div class="post-metadata">

**Author:** ![PandKing](https://avatars.discourse-cdn.com/v4/letter/p/258eb7/32.png) [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Post date:** [April 20, 2018, 4:56pm UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770/3 "2018-04-20T16:56:10Z")

</div>

Yea looked at that but it doesn't fit the business need.

I want to use logstash as my traffic cop.

- Everything goes to ES
- Critical events go to our monitoring solution.
- Specific event ID's go to our SAS solution for PCI.

The first two are easy but the 3rd I have a list of about 100 event ID's to target.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 21, 2018, 3:00am UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770/4 "2018-04-21T03:00:48Z")

</div>

I know this is might be a bit longwinded but something like this should work:

```
output {
  if [field] =~ "(EventID1|EventID2|EventID3|etc...)" {
    output config....
  }
}
```

---

<div class="post-metadata">

**Author:** ![PandKing](https://avatars.discourse-cdn.com/v4/letter/p/258eb7/32.png) [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Post date:** [April 22, 2018, 9:56pm UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770/5 "2018-04-22T21:56:44Z")

</div>

Yep that would do it,  
Was hoping to find a way to pull out the list into a macro or something.

Like if [event\_it] in $list type of expression so the list could be a managed flat file or something.

Thanks Walker i'll post results.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 22, 2018, 11:17pm UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770/6 "2018-04-22T23:17:11Z")

</div>

Based on the example documentation, it looks like you can use ranges as well. You may also be able to use regex or wildcard. I've not tried to get as granular as you are going so I don't really know what's possible.

---

<div class="post-metadata">

**Author:** ![PandKing](https://avatars.discourse-cdn.com/v4/letter/p/258eb7/32.png) [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Post date:** [April 30, 2018, 8:00pm UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770/7 "2018-04-30T20:00:26Z")

</div>

Using eventcreate on windows to create an windows event\_id of 999. I can see it in the debug logs and I can see it if I write it out to file without the filter but I CANNOT seem to get this rule to fire.  
Any help would be appreciated.

```
  if [type]=="wineventlog" and [event_id]=="999" {
     file {
     path => "/opt/logs/logstash/%{host}-eventid.json"
     codec => "json_lines"
     }
    }
  if [type]=="wineventlog" and "DC" in [tags] {
    tcp {
    host => "loghost"
    port => "5142"
    mode => "client"
    codec => "json_lines"
    }
```

---

<div class="post-metadata">

**Author:** ![PandKing](https://avatars.discourse-cdn.com/v4/letter/p/258eb7/32.png) [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Post date:** [April 30, 2018, 8:34pm UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770/8 "2018-04-30T20:34:17Z")

</div>

Update: Found a reply from Magnus Bäck on another post. event\_id is a numeric type 'm' so you are required to used a non string match.  
The question is how can I match multiple values.

[event\_id]==999

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2018, 8:34pm UTC](https://discuss.elastic.co/t/filter-winlogbeat-by-eventid/128770/9 "2018-05-28T20:34:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
