Filter with winlogbeat

@BeyondRAM
When querying for Windows paths, you need escape some characters in KQL. There were few related posts which I found on discussion forum itself, may be try searching for your issues first :slight_smile:

Nevertheless, you can refer: Wildcard filter on a Windows path - #3 by willemdh or Issue on query string query for URL search based on if its on Discover tab or DevConsole respectively.

Also, I would suggest you to use path_hierarchy tokenizer for your your field which stores filesystem paths. For more information, please refer Path hierarchy tokenizer | Elasticsearch Guide [8.6] | Elastic