# Filter with winlogbeat

**URL:** <https://discuss.elastic.co/t/filter-with-winlogbeat/324621>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [February 3, 2023, 8:47am UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621 "2023-02-03T08:47:49Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [February 3, 2023, 1:33pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621/2 "2023-02-03T13:33:29Z")

</div>

@BeyondRAM  
When querying for Windows paths, you need escape some characters in KQL. There were few related posts which I found on discussion forum itself, may be try searching for your issues first 🙂

Nevertheless, you can refer: [Wildcard filter on a Windows path - #3 by willemdh](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/3) or [Issue on query string query for URL search](https://discuss.elastic.co/t/issue-on-query-string-query-for-url-search/152863) based on if its on Discover tab or DevConsole respectively.

Also, I would suggest you to use `path_hierarchy` tokenizer for your your field which stores filesystem paths. For more information, please refer **[Path hierarchy tokenizer | Elasticsearch Guide [8.6] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-pathhierarchy-tokenizer.html)**

---

_[View the full topic](https://discuss.elastic.co/t/filter-with-winlogbeat/324621)._
