# Winlogbeat filter not working

**URL:** <https://discuss.elastic.co/t/winlogbeat-filter-not-working/234670>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 28, 2020, 6:35am UTC](https://discuss.elastic.co/t/winlogbeat-filter-not-working/234670 "2020-05-28T06:35:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krishna\_MS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishna_ms/32/69255_2.png) [@Krishna\_MS](https://discuss.elastic.co/u/Krishna_MS)\
**Post date:** [May 28, 2020, 6:35am UTC](https://discuss.elastic.co/t/winlogbeat-filter-not-working/234670/1 "2020-05-28T06:35:12Z")

</div>

Hi,

I have installed Winlogbeat 7.6.2 and configured the following filter.

winlogbeat.event\_logs:

- name: Application  
event\_id: 1000,1002,1001  
ignore\_older: 72h  
level: critical, error, warning

- name: System  
event\_id: 4740,4728,4732,4756,4735,4724,4625,1102  
ignore\_older: 72h  
level: critical, error, warning

- name: DFS Replication  
event\_id: 5004,5014,4304,5002  
ignore\_older: 72h  
level: critical, error, warning, information

- name: Security  
event\_id: 4624, 4625, 4728, 4732, 4756, 4735  
ignore\_older: 72h  
processors:

However i am still getting events with username ending with $ and SYSTEM accounts.

Could u please help me out?

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [May 28, 2020, 1:11pm UTC](https://discuss.elastic.co/t/winlogbeat-filter-not-working/234670/2 "2020-05-28T13:11:14Z")

</div>

hi @Krishna_MS, can you try removing the `winlog` prefix from the field name and let us know if it worked?  
ex:

```auto
- equals.event_id: 4624

```

instead of

```auto
- equals.winlog.event_id: 4624

```

---

<div class="post-metadata">

**Author:** ![Krishna\_MS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishna_ms/32/69255_2.png) [@Krishna\_MS](https://discuss.elastic.co/u/Krishna_MS)\
**Post date:** [May 29, 2020, 2:11am UTC](https://discuss.elastic.co/t/winlogbeat-filter-not-working/234670/3 "2020-05-29T02:11:36Z")

</div>

Hi,

I changed to

- equals.event\_id: 4624  
- equals.event\_id: 4634  
- or:  
- equals.winlog.event\_data.TargetUserName: 'SYSTEM'  
- regexp.winlog.event\_data.TargetUserName: '^SQL.\*$'

I also tried this

- equals.event\_id: 4624  
- equals.event\_id: 4634  
- or:  
- equals.event\_data.TargetUserName: 'SYSTEM'  
- regexp.event\_data.TargetUserName: '^SQL.\*$'

It is not working. It still logs events with username ending with $

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2020, 2:11am UTC](https://discuss.elastic.co/t/winlogbeat-filter-not-working/234670/4 "2020-06-26T02:11:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
