Based on your logs filtering conditions are passed to Winlogbeat correctly. You might need to filter out more events, if you would like to decrease the number of events further.
It's weird because I still see mostly messages that are tagged as "information". When I check my event history I don't see any decrease in the events amount. Is there any other way to test Winlogbeat outside the Graylog environment?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.