# Help with Winlogbeat yaml config

**URL:** <https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041>\
**Category:** Beats\
**Created:** [November 30, 2019, 9:30pm UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041 "2019-11-30T21:30:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![xxstyler20xx](https://avatars.discourse-cdn.com/v4/letter/x/6f9a4e/32.png) [@xxstyler20xx](https://discuss.elastic.co/u/xxstyler20xx)\
**Post date:** [November 30, 2019, 9:30pm UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041/1 "2019-11-30T21:30:15Z")

</div>

Hello I'm new to this and I just can't find the rigt answer for my problem..  
I'm stuck with my winlogbeat yaml conf.  
//  
event\_logs:

- name: Security  
event\_id: 4625, 4624  
processors:
- drop\_fields:  
fields: ["message"]  
//  
this works

But now I want to drop event\_id 4624 when NOT:

- equals.event\_data.TargetUserName: Administrator  
OR NOT
- equals.event\_data.TargetUserName: root

I tried many different ways I found on the internet but no matter how I write it I just get errors...

Thanks for help!  
{NOTE: massage field should always drop.. }

---

<div class="post-metadata">

**Author:** ![xxstyler20xx](https://avatars.discourse-cdn.com/v4/letter/x/6f9a4e/32.png) [@xxstyler20xx](https://discuss.elastic.co/u/xxstyler20xx)\
**Post date:** [December 1, 2019, 5:40pm UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041/2 "2019-12-01T17:40:37Z")

</div>

nobody?? 😕

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [December 1, 2019, 11:13pm UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041/3 "2019-12-01T23:13:48Z")

</div>

I don't understand your logic. Let's test with 3 matching event\_id's, one each where TargetUserName is "Administrator", "root", and "bob".

You drop "Administrator" because it is not "root". You drop "root" because it is not "Administrator", you drop "bob" because both match. It looks your logic logic drops everything.

If that doesn't help, your syntax and error messages would help.

---

<div class="post-metadata">

**Author:** ![xxstyler20xx](https://avatars.discourse-cdn.com/v4/letter/x/6f9a4e/32.png) [@xxstyler20xx](https://discuss.elastic.co/u/xxstyler20xx)\
**Post date:** [December 1, 2019, 11:27pm UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041/4 "2019-12-01T23:27:25Z")

</div>

Yeah.. Could be ..I‘m really pretty new to this.. So forget about the mistakes I made..

I want to only get event 4624 logged when the username is Administrator or root

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [December 2, 2019, 12:55am UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041/5 "2019-12-02T00:55:19Z")

</div>

I think it's very confusing logic, someone else on our team handles these, I tend to send it all to logstash and let it sort it out. But, I think it's something like this:

```
processors:
- drop_event:
    when:
      and:
      - not:
        - or:
          - equals.TargetUserName: Administrator
          - equals.TargetUserName: root
      - equals.event_data.event_id: 4624

```

Use a YAML lint [tool](http://www.yamllint.com/) to validate your file before using it in winlogbeat.

---

<div class="post-metadata">

**Author:** ![xxstyler20xx](https://avatars.discourse-cdn.com/v4/letter/x/6f9a4e/32.png) [@xxstyler20xx](https://discuss.elastic.co/u/xxstyler20xx)\
**Post date:** [December 2, 2019, 4:42am UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041/6 "2019-12-02T04:42:48Z")

</div>

Thanks very much I will give it a shot..  
why is it confusing .. don‘t get your point.. for me your config is confusing :‘)

because i want drop event 6524 when username not administrator or root..

the code you send me looks like not drop  
4624, or admin , or root .. 😄

The next thing is.. in other posts they write „winlog.eventdata.targetusername“ ..  
So thats confusing for me .. also the point with the - symbol.. depends on the page dou look everyone writes different and i get only „missing key here, wrong symbol here.. and so an errors..

Also there is no team that handles anything..

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [December 2, 2019, 1:56pm UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041/7 "2019-12-02T13:56:56Z")

</div>

I think most of those errors are YAML formatting errors. I think it will help you to validate the YAML with a linter (linked above) to get valid YAML before testing in beats.

Dashes are array syntax in YAML see the array section [here](https://rollout.io/blog/yaml-tutorial-everything-you-need-get-started/).

In my guess above, the and can have a '-' and it's still valid yaml, it's just a 1 element array. The "- not" and "- equals.event\_data.event\_id" are elements of the "and", in the doc . The "- or" is a complex conditional also with 2 elements.

YAML "equals.event\_data.event\_id: 4624" is the same as

```
equals:
  event_data.event_id: 4624

```

Just different format, adding to the confustion.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2019, 3:56pm UTC](https://discuss.elastic.co/t/help-with-winlogbeat-yaml-config/210041/8 "2019-12-30T15:56:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
