# Unable to filter more than 22 eventIDs

**URL:** <https://discuss.elastic.co/t/unable-to-filter-more-than-22-eventids/48358>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 25, 2016, 10:49pm UTC](https://discuss.elastic.co/t/unable-to-filter-more-than-22-eventids/48358 "2016-04-25T22:49:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alreanaes](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Alreanaes](https://discuss.elastic.co/u/Alreanaes)\
**Post date:** [April 25, 2016, 10:49pm UTC](https://discuss.elastic.co/t/unable-to-filter-more-than-22-eventids/48358/1 "2016-04-25T22:49:14Z")

</div>

The relevant output from -e -d "\*"

```
DBG WinEventLog[ForwardedEvents] using subscription query=<QueryList>
  <Query Id="0">
    <Select Path="ForwardedEvents">*[System[(EventID=1 or EventID=2 or EventID=3 or EventID=4 or EventID=5 or EventID=6 or EventID=7 or EventID=8 or EventID=9 or EventID=10 or EventID=11 or EventID=12 or EventID=13 or EventID=14 or EventID=15 or EventID=16 or EventID=17 or EventID=18 or EventID=19 or EventID=20 or EventID=21 or EventID=22 or EventID=23 or EventID=24)]]</Select>
  </Query>
</QueryList>
WARN EventLog[ForwardedEvents] Open() error. No events will be read from this source. The specified query is invalid.

```

According to [KB970453](https://support.microsoft.com/en-us/kb/970453) , more than 22 event sources need to be split into seperate queries.

I have successfully tested the following query in event viewer where the above fails

```
<QueryList>
  <Query Id="0" Path="ForwardedEvents">
    <Select Path="ForwardedEvents">*[System[(EventID=1 or EventID=2 or EventID=3 or EventID=4 or EventID=5 or EventID=6 or EventID=7 or EventID=8 or EventID=9 or EventID=10 or EventID=11 or EventID=12 or EventID=13 or EventID=14 or EventID=15 or EventID=16 or EventID=17 or EventID=18 or EventID=19 or EventID=20 or EventID=21 or EventID=22 or EventID=23)]]</Select>
  </Query>
  <Query Id="1" Path="ForwardedEvents">
    <Select Path="ForwardedEvents">*[System[(EventID=24)]]</Select>
</QueryList>
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 25, 2016, 11:44pm UTC](https://discuss.elastic.co/t/unable-to-filter-more-than-22-eventids/48358/2 "2016-04-25T23:44:35Z")

</div>

Thanks for reporting this. If only Microsoft had it in there documentation we would have accounted for it. Can you please open a issue in the [elastic/beats](https://github.com/elastic/beats/issues/new) repo for this problem? And what OS were you trying this on?

For starters we can document the current limitation in our reference docs. And longer term I want to add support for more advanced queries and also raw XML queries which should make it possible to work around the limit.

---

<div class="post-metadata">

**Author:** ![Alreanaes](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Alreanaes](https://discuss.elastic.co/u/Alreanaes)\
**Post date:** [April 27, 2016, 12:53pm UTC](https://discuss.elastic.co/t/unable-to-filter-more-than-22-eventids/48358/3 "2016-04-27T12:53:08Z")

</div>

I encountered this error on 2008R2 and have also demonstrated it on 2012R2.

Advanced queries and raw XML would be great. In the meantime I've come up with an, _admittedly hacky_, workaround to show off a working POC of winlogbeat.

```
- name: ForwardedEvents
  event_id: 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23
- name: ForwardedEvents
  event_id: 24
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2016, 12:53pm UTC](https://discuss.elastic.co/t/unable-to-filter-more-than-22-eventids/48358/4 "2016-05-18T12:53:44Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
