I am very to ELK. I've setup a GPO which forwards sysmon and sercurity logs to a server. Then I have winlogbeat which sends the log to logstash. Everything works like a charm except now I am trying to filter the events I am not interested in.
Here is an example
So in Winlogbeat I created the following processor
- equals.event_data.TargetUserName: $Printer_Maestro$
Unfortunately the logs are still be sent.
Thanks in advance,