# Winlogbeat filter

**URL:** <https://discuss.elastic.co/t/winlogbeat-filter/140772>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 19, 2018, 2:58pm UTC](https://discuss.elastic.co/t/winlogbeat-filter/140772 "2018-07-19T14:58:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![8c8459cec5b62e5054b6](https://avatars.discourse-cdn.com/v4/letter/8/5e9695/32.png) [@8c8459cec5b62e5054b6](https://discuss.elastic.co/u/8c8459cec5b62e5054b6)\
**Post date:** [July 19, 2018, 2:58pm UTC](https://discuss.elastic.co/t/winlogbeat-filter/140772/1 "2018-07-19T14:58:26Z")

</div>

Hey  
Please help.  
The boss set the task to configure logging of events of deletion, creation, modification and files on the file server.  
The ELK server is set up, it's time to install winlogbeeat on the file server and configure the transfer of the necessary events. Made configure winlogbeat, events are sent to the server ELK, but the events of too much and too much junk. I picked a few event\_id, set up fee only them, but the events still a lot to have found out some required parameters event\_data.AccessMask that I need. I'm trying to set up filtering by the event\_data parameter.Access Mask unfortunately does not work filtering. Help please

```auto
winlogbeat.event log:
  - name: security
    event code: 4656, 4663

```

you need to filter all event\_data.Access Mask other than as below.  
event\_data.Access Mask,  
0x10000  
0x20  
0x4  
0x2  
0x40  
Help please

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 19, 2018, 9:26pm UTC](https://discuss.elastic.co/t/winlogbeat-filter/140772/2 "2018-07-19T21:26:59Z")

</div>

You can you a drop\_event process to drop events that do not match your condition.

```auto
winlogbeat.event log:
- name: security
  event code: 4656, 4663
  processors:
  - drop_event:
      when.not.or:
        - equals.event_data.AccessMask: '0x10000'
        - equals.event_data.AccessMask: '0x20'
        - equals.event_data.AccessMask: '0x4'
        - equals.event_data.AccessMask: '0x2'
        - equals.event_data.AccessMask: '0x40'

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2018, 9:36pm UTC](https://discuss.elastic.co/t/winlogbeat-filter/140772/3 "2018-08-16T21:36:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
