# Filtering Winlogbeat on Event ID

**URL:** <https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 9, 2016, 1:57pm UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899 "2016-03-09T13:57:53Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sean\_Lamm](https://avatars.discourse-cdn.com/v4/letter/s/dfb087/32.png) [@Sean\_Lamm](https://discuss.elastic.co/u/Sean_Lamm)\
**Post date:** [March 9, 2016, 1:57pm UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899/1 "2016-03-09T13:57:53Z")

</div>

Is there a way to filter events in winlogbeat so I am only sending certain event id's? I am specifically looking to send only event id 8003 for now to limit the transmission of data to our ELK stack. I have around 20,000 machines that could send data.

Thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 9, 2016, 2:27pm UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899/2 "2016-03-09T14:27:56Z")

</div>

That's a lot of machines. See the discussion here: [Filtering Winlogbeat Events](https://discuss.elastic.co/t/filtering-winlogbeat-events/41116)

Summarizing that thread, a filtering feature is being added to all beats. Relevant here is `drop_event` in the [proposal](https://github.com/elastic/beats/issues/45). Additionally there is a [request](https://github.com/elastic/beats/issues/1054) for using XPath queries in Winlogbeat, but that's further out ([#1053](https://github.com/elastic/beats/issues/1053) is first in line).

At the current time you need to use Logstash to do filtering.

---

<div class="post-metadata">

**Author:** ![Sean\_Lamm](https://avatars.discourse-cdn.com/v4/letter/s/dfb087/32.png) [@Sean\_Lamm](https://discuss.elastic.co/u/Sean_Lamm)\
**Post date:** [March 9, 2016, 2:30pm UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899/3 "2016-03-09T14:30:23Z")

</div>

Any creative ideas I can try now to limit the data flow to the ELK stack?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 9, 2016, 2:47pm UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899/4 "2016-03-09T14:47:25Z")

</div>

With Logstash you can do this:

```auto
input {
  beats {
    port => 5044
  }
}

filter {
  if [type] == "wineventlog" and [event_id] != 8003 {
    drop { } 
  }
}

output {
  elasticsearch {
    hosts => "localhost:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![Sean\_Lamm](https://avatars.discourse-cdn.com/v4/letter/s/dfb087/32.png) [@Sean\_Lamm](https://discuss.elastic.co/u/Sean_Lamm)\
**Post date:** [March 9, 2016, 2:51pm UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899/5 "2016-03-09T14:51:03Z")

</div>

Thanks for the quick responses!

This will only prevent the events from being captured by logstash and not prevent winlogbeat from sending them to the logstash server. I really am looking for a way to prevent the traffic flow to the logstash server.

How long until the drop\_event feature will be added? Can I beta test the release?

Thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 9, 2016, 3:09pm UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899/6 "2016-03-09T15:09:12Z")

</div>

The feature is targeted to [v5](https://www.elastic.co/v5) (the next major release), but it hasn't been implemented so there's nothing to test yet.

---

<div class="post-metadata">

**Author:** ![Dave\_Foster](https://avatars.discourse-cdn.com/v4/letter/d/ecb155/32.png) [@Dave\_Foster](https://discuss.elastic.co/u/Dave_Foster)\
**Post date:** [March 10, 2016, 4:14am UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899/7 "2016-03-10T04:14:38Z")

</div>

Thx for this reply. I was actually looking for something similar. In my case there seemed to be a syntax problem with the above. I used the following (changing the eventID to event\_id and removing the quotes around the 4634...

```auto
input {
  beats {
    port => 5040
# ssl => false
# ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
# ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  }
}

filter {
  if [type] == "wineventlog" and [event_id] == 4624 or [event_id] == 4634 {
    drop { } 
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    sniffing => true
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 14, 2016, 8:49pm UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899/8 "2016-03-14T20:49:54Z")

</div>

Thanks @Dave_Foster. I updated my post to reflect the changes you made.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:54pm UTC](https://discuss.elastic.co/t/filtering-winlogbeat-on-event-id/43899/9 "2017-07-05T21:54:38Z")

</div>


