Hi,
In SIEM systems events can be discard or filter to safe diskspace and avoid overloading SIEM from noisy events. This way SIEM resources can be managed at optimum levels.
For example windows event 5156 from all agents to be filtered or from specific agent.
How to achieve this from Elastic SIEM UI or some other manageable way ?