# Winlogbeat Alert for certain users in Windows PC

**URL:** <https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 5, 2023, 4:15am UTC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506 "2023-01-05T04:15:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![amis349](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@amis349](https://discuss.elastic.co/u/amis349)\
**Post date:** [January 5, 2023, 4:15am UTC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506/1 "2023-01-05T04:15:40Z")

</div>

Okay I have looked around and found different iterations of a solution. However I am running into a road block, the winlogbeats (below) are not dropping the events for that targetusername or even the event ID. All logs are still being processed into my stream/sidecar

Here is the winlogbeat I have used (does not work)

```auto
winlogbeat.event_logs:
- name: Security
  processors:
  - drop_event:
      when:
        and:
          - or:
            - equals.winlog.event_id: 4624
            - equals.winlog.event_id: 4634
            - equals.winlog.event_id: 4672
          - or:
            - equals.winlog.event_data.TargetUserName: "pcuser01"

```

I still see log 4672 and username "pcuser01" when it logs into a system (that holds the winlogbeat config (via sidecar agent)

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [January 6, 2023, 11:10am UTC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506/2 "2023-01-06T11:10:53Z")

</div>

For an "OR" operator, you need to provide 2 operands to compare between. In case of username, you are using OR but only one operand is present and is not a valid logical operation.  
If I understand correctly, you essentially want to perform AND operation on "pcuser01" and one of those 3 event\_id values ? If yes, then you do not need the "OR" operator for the username field and equality check can be put directly under AND.

---

<div class="post-metadata">

**Author:** ![amis349](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@amis349](https://discuss.elastic.co/u/amis349)\
**Post date:** [January 7, 2023, 12:41am UTC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506/3 "2023-01-07T00:41:08Z")

</div>

Okay so it should look like...

```auto
winlogbeat.event_logs:
- name: Security
  processors:
  - drop_event:
      when:
        and:
          - equals.winlog.event_id: 4624
          - equals.winlog.event_id: 4634
          - equals.winlog.event_id: 4672
          - equals.winlog.event_data.TargetUserName: "pcuser01"

```

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [January 9, 2023, 7:26am UTC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506/4 "2023-01-09T07:26:56Z")

</div>

I guess this won't work since a single event cannot have multiple event IDs. You need keep event IDs in OR with an AND with username, something like:

```auto
- drop_event:
      when:
        and:
          - or :
            - equals.winlog.event_id: 4624
            - equals.winlog.event_id: 4634
            - equals.winlog.event_id: 4672
          - equals.winlog.event_data.TargetUserName: "pcuser01"

```

---

<div class="post-metadata">

**Author:** ![amis349](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@amis349](https://discuss.elastic.co/u/amis349)\
**Post date:** [January 17, 2023, 3:24am UTC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506/5 "2023-01-17T03:24:11Z")

</div>

> [@amis349](#):
>
> `equals.winlog.event_data.TargetUserName: "pcuser01"`

I think I was looking at this wrong. I decided to only ingest what I am looking to see. but also add filtering. Here is what I am doing but I want to remove the noise from the registry that is associated to the logins for windows (EVENT 4657). I tried layering winlogbeat configurations but I still got thousands of logs haha.

```auto
winlogbeat:
  event_logs:
   - name: Security
     event_id: 4672, 4657
   - name: System
     event_id: 7045

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2023, 5:24am UTC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506/6 "2023-02-14T05:24:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
