# Winlogbeat - drop\_event (multiple event ID's with specific rules)

**URL:** <https://discuss.elastic.co/t/winlogbeat-drop-event-multiple-event-ids-with-specific-rules/252822>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 21, 2020, 11:03am UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-multiple-event-ids-with-specific-rules/252822 "2020-10-21T11:03:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![0xf](https://avatars.discourse-cdn.com/v4/letter/0/e47774/32.png) [@0xf](https://discuss.elastic.co/u/0xf)\
**Post date:** [October 21, 2020, 11:03am UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-multiple-event-ids-with-specific-rules/252822/1 "2020-10-21T11:03:46Z")

</div>

Okay so im having a hard time solving this puzzle. Tried almost everything and i cant really solve it by myself, any ideas?

So i have 2 event ID's:  
winlog.event\_id: 4624  
winlog.event\_id: 4672

What i want to do is i want to exclude 3-4 or more UserSID Usernames etc. and i only want to specify every event ID's. So for example which applies to 4624 is only applies to 4624. Which applies to 4672 only applies to 4672. etc.

The code i have right now is this:

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9a3ddcd32006a8df3f1252f91557de6805790552.png)

I think i probably have 'and', 'or' problem. Not sure tho.

Note that i might want to add ore event ID's in the future.

---

<div class="post-metadata">

**Author:** ![mazoutte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mazoutte/32/120188_2.png) [@mazoutte](https://discuss.elastic.co/u/mazoutte)\
**Post date:** [October 21, 2020, 12:36pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-multiple-event-ids-with-specific-rules/252822/2 "2020-10-21T12:36:25Z")

</div>

Hello,

You were close actually 😉

Can you copy/past your config next time please, then we can correct directly with your config.

You can try with one more "or" condition :

```
  - equals.winlog.event_id: 4672
  - or:
    - equals.winlog.event_data.SubjectUserName: 'LOCAL SERVICE'
    - equals.winlog.event_data.SubjectUserSid: '^S-1-5-21.*'
    - equals.winlog.event_data.SubjectUserSid: 'S-1-5-20'
    - equals.winlog.event_data.SubjectUserSid: 'S-1-5-19'

```

Regards,  
Luc

---

<div class="post-metadata">

**Author:** ![0xf](https://avatars.discourse-cdn.com/v4/letter/0/e47774/32.png) [@0xf](https://discuss.elastic.co/u/0xf)\
**Post date:** [October 21, 2020, 1:08pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-multiple-event-ids-with-specific-rules/252822/3 "2020-10-21T13:08:48Z")

</div>

Original Code:

processors:

```
- drop_event.when.or:

  - equals.winlog.event_id: 4624

  # - regexp.winlog.event_data.TargetUserSid: "^S-1-5-21.*"

  # - equals.winlog.event_data.SubjectUserSid: 'S-1-5-18'

  # - equals.winlog.event_data.TargetUserSid: 'S-1-0-0'

  # - equals.winlog.event_data.TargetUserSid: 'S-1-5-18 \t'

  - equals.winlog.event_data.TargetUserName: 'SYSTEM'

  - and:

    - equals.winlog.event_id: 4672

    - equals.winlog.event_data.SubjectUserName: 'LOCAL SERVICE'

    - regexp.winlog.event_data.SubjectUserSid: '^S-1-5-21.*'

    - equals.winlog.event_data.SubjectUserSid: 'S-1-5-20'

    - equals.winlog.event_data.SubjectUserSid: 'S-1-5-19'
```

---

<div class="post-metadata">

**Author:** ![0xf](https://avatars.discourse-cdn.com/v4/letter/0/e47774/32.png) [@0xf](https://discuss.elastic.co/u/0xf)\
**Post date:** [October 21, 2020, 1:10pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-multiple-event-ids-with-specific-rules/252822/4 "2020-10-21T13:10:13Z")

</div>

Yes ofcourse! My apologies! 😃

Edited! So it should look like this if im correct? :

processors:

```
- drop_event.when.or:

  - equals.winlog.event_id: 4624

  # - regexp.winlog.event_data.TargetUserSid: "^S-1-5-21.*"

  # - equals.winlog.event_data.SubjectUserSid: 'S-1-5-18'

  # - equals.winlog.event_data.TargetUserSid: 'S-1-0-0'

  # - equals.winlog.event_data.TargetUserSid: 'S-1-5-18 \t'

  - equals.winlog.event_data.TargetUserName: 'SYSTEM'

  - and:

    - equals.winlog.event_id: 4672

    - or:

      - equals.winlog.event_data.SubjectUserName: 'LOCAL SERVICE'

      - regexp.winlog.event_data.SubjectUserSid: '^S-1-5-21.*'

      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-20'

      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-19'
```

---

<div class="post-metadata">

**Author:** ![0xf](https://avatars.discourse-cdn.com/v4/letter/0/e47774/32.png) [@0xf](https://discuss.elastic.co/u/0xf)\
**Post date:** [October 21, 2020, 1:24pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-multiple-event-ids-with-specific-rules/252822/5 "2020-10-21T13:24:25Z")

</div>

Im also curious, so if i want to add more event id, this will be just an example but:  
Please note that event id 9999 is just an example.

But every event when its ends, i need to add "- and:" and then the new event id.  
Its really confusing at first to be honest but i gotcha.

**Edit** : After i tested i actually dont get event id 4624. So for example i still want to get every event id 4624 except those one which has TargetUserame: 'System' in this case. So it has System? Drop the event, let every other event pass within 4624.

Big thanks  
/b

```
processors:
- drop_event.when.or:
  - equals.winlog.event_id: 4624
  # - regexp.winlog.event_data.TargetUserSid: "^S-1-5-21.*"
  # - equals.winlog.event_data.SubjectUserSid: 'S-1-5-18'
  # - equals.winlog.event_data.TargetUserSid: 'S-1-0-0'
  # - equals.winlog.event_data.TargetUserSid: 'S-1-5-18 \t'
  - equals.winlog.event_data.TargetUserName: 'SYSTEM'
  - and:
    - equals.winlog.event_id: 4672
    - or:
      - equals.winlog.event_data.SubjectUserName: 'LOCAL SERVICE'
      - regexp.winlog.event_data.SubjectUserSid: '^S-1-5-21.*'
      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-20'
      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-19'
  - and:
    - equals.winlog.event_id: 9999
    - or:
      - equals.winlog.event_data.SubjectUserName: 'LOCAL SERVICE'
      - regexp.winlog.event_data.SubjectUserSid: '^S-1-5-21.*'
      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-20'
      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-19'
```

---

<div class="post-metadata">

**Author:** ![mazoutte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mazoutte/32/120188_2.png) [@mazoutte](https://discuss.elastic.co/u/mazoutte)\
**Post date:** [October 21, 2020, 2:06pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-multiple-event-ids-with-specific-rules/252822/6 "2020-10-21T14:06:06Z")

</div>

> [@0xf](#):
>
> us, so if i want to add more event id, this will be just an example but:  
> Please note that event id 9999 is just an example.

Remember we use "Drop" Event When "something".  
For your question regarding dropping "4624 And SYSTEM" :

```auto
processors:
- drop_event.when.or:
  - and:
    - equals.winlog.event_id: 4624
    - equals.winlog.event_data.TargetUserName: 'SYSTEM'
  - and:
    - equals.winlog.event_id: 4672
    - or:
      - equals.winlog.event_data.SubjectUserName: 'LOCAL SERVICE'
      - regexp.winlog.event_data.SubjectUserSid: '^S-1-5-21.*'
      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-20'
      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-19'
  - and:
    - equals.winlog.event_id: 9999
    - or:
      - equals.winlog.event_data.SubjectUserName: 'LOCAL SERVICE'
      - regexp.winlog.event_data.SubjectUserSid: '^S-1-5-21.*'
      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-20'
      - equals.winlog.event_data.SubjectUserSid: 'S-1-5-19'

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2020, 4:06pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-multiple-event-ids-with-specific-rules/252822/7 "2020-11-18T16:06:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
