# Proper Syntax for filtering forwarded events?

**URL:** <https://discuss.elastic.co/t/proper-syntax-for-filtering-forwarded-events/233025>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 18, 2020, 3:04am UTC](https://discuss.elastic.co/t/proper-syntax-for-filtering-forwarded-events/233025 "2020-05-18T03:04:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![almathden](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@almathden](https://discuss.elastic.co/u/almathden)\
**Post date:** [May 18, 2020, 3:04am UTC](https://discuss.elastic.co/t/proper-syntax-for-filtering-forwarded-events/233025/1 "2020-05-18T03:04:31Z")

</div>

So this is a two-fer, filtering and processing with the security module

[https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-module-security.html](https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-module-security.html)

What is the proper syntax for this?

The article has this, so that the script applies to the security entries - but in my case they're "ForwardedEvents" and applying it to that category doesn't seem to do anything.

Same for filtering by event ID - how do I manage that? Normally you can do it by name (Security, Application, System) and then ID - how can I filter by name/ID while inside ForwardedEvents?

Or do I just have to filter by event ID and then 'drop' by name when it hits logstash? I was hoping to do this all from the winlogbeat config side but wherever works, I guess!

Thanks,  
-Brian

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2020, 3:04am UTC](https://discuss.elastic.co/t/proper-syntax-for-filtering-forwarded-events/233025/2 "2020-06-15T03:04:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
