# How to collect more than 22 event ids with winlogbeat?

**URL:** <https://discuss.elastic.co/t/how-to-collect-more-than-22-event-ids-with-winlogbeat/124274>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 16, 2018, 10:44am UTC](https://discuss.elastic.co/t/how-to-collect-more-than-22-event-ids-with-winlogbeat/124274 "2018-03-16T10:44:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![FanteG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fanteg/32/70811_2.png) [@FanteG](https://discuss.elastic.co/u/FanteG)\
**Post date:** [March 16, 2018, 10:44am UTC](https://discuss.elastic.co/t/how-to-collect-more-than-22-event-ids-with-winlogbeat/124274/1 "2018-03-16T10:44:26Z")

</div>

I've got a task to collect over 500 events from DC with winlogbeat. But windows got a limit 22 events to query. I'm using version 6.1.2. I've tried with processors like this:

```
winlogbeat.event_logs:
  - name: Security
                   
processors:
  - drop_event.when.not.or:
    - equals.event_id: 4618
...

```

but with these settings client doesn't work, nothing in logs. If I run it from exe file it just starts and stops with no error.  
If I try to do like it was written in the official manual:

```
winlogbeat.event_logs:
  - name: Security
    event_id: ...                
    processors:
      - drop_event.when.not.or:
        - equals.event_id: 4618
...

```

client just crashes with "invalid event log key processors found". Also I've tried to create new custom view and take event from there, but apparently it also has query limit to 22 events.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 16, 2018, 2:03pm UTC](https://discuss.elastic.co/t/how-to-collect-more-than-22-event-ids-with-winlogbeat/124274/2 "2018-03-16T14:03:07Z")

</div>

This will be [fixed](https://github.com/elastic/beats/pull/6217) in Winlogbeat 6.3.0. You can try the snapshot build if you like: [https://s3-us-west-2.amazonaws.com/beats-package-snapshots/index.html?prefix=winlogbeat/](https://s3-us-west-2.amazonaws.com/beats-package-snapshots/index.html?prefix=winlogbeat/)

As a workaround for the processors error you can try using `processors` at the top-level and it will apply to all events.

```auto
winlogbeat.event_logs:
  - name: Security
          
processors:
- drop_event.when.not.or:
  - equals.event_id: 4618

```

And don't forget that `event_ids` supports ranges which might help you slim down the list. Like `event_ids: 1-99, 4000-5000, !4889`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2018, 2:03pm UTC](https://discuss.elastic.co/t/how-to-collect-more-than-22-event-ids-with-winlogbeat/124274/3 "2018-04-13T14:03:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
