# Winlogbeat Filtering Issue

**URL:** <https://discuss.elastic.co/t/winlogbeat-filtering-issue/261695>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 20, 2021, 7:32pm UTC](https://discuss.elastic.co/t/winlogbeat-filtering-issue/261695 "2021-01-20T19:32:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jcor](https://avatars.discourse-cdn.com/v4/letter/j/8797f3/32.png) [@jcor](https://discuss.elastic.co/u/jcor)\
**Post date:** [January 20, 2021, 7:32pm UTC](https://discuss.elastic.co/t/winlogbeat-filtering-issue/261695/1 "2021-01-20T19:32:15Z")

</div>

Hi folks,  
I've run into a weird issue. I have two separate clusters. One is my personal lab and the other is a dev lab. I'm trying to drop a specific winlogevent id as sysmon is very noisey and not required for what I am doing.

In my personal lab I am able to drop event X as designed and documented by others. But on the dev cluster, with the same exact syntax winlogbeats does not drop the event id.

I am at a loss, event id 17 wont shut up. I've restarted the services after pushing out new configs and event id 17 is still being shipped. I mirrored the config from the personal lab to match the dev lab and dev lab still was shipping over the wrong data.

**Dev Config Below**

```auto
  winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h

  - name: System

  - name: Security
    #level: critical, error, warning
    ignore_older: 1h
    processors:
      - drop_event.when.or:
          - equals.winlog.event_id: 5145 # Filtering network share object access
          - equals.winlog.event_id: 4656
          - equals.winlog.event_id: 5152 #Packet blocked
          - equals.winlog.event_id: 4658
          - equals.winlog.event_id: 5156 #Triggered very often by both Tanium and Radiant 
          - equals.winlog.event_id: 5158 #local Bind permitted
          - equals.winlog.event_id: 4689 #Process exit
          - equals.winlog.event_id: 4688 #process creation
          - equals.winlog.event_id: 5157 #process creation
          - equals.winlog.event_id: 5447 #process creation
          
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

  - name: Microsoft-Windows-Sysmon/Operational
    ignore_older: 1h
    processors:
      - drop_event.when.or:
          - equals.winlog.event_id: 17
      - script:
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

  - name: Windows PowerShell
    ignore_older: 1h
    event_id: 400, 403, 600, 800
    processors:
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: Microsoft-Windows-PowerShell/Operational
    ignore_older: 1h
    event_id: 4103, 4104, 4105, 4106
    processors:
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: ForwardedEvents
    tags: [forwarded]
    processors:
      - script:
          when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js
      - script:
          when.equals.winlog.channel: Windows PowerShell
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-PowerShell/Operational
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

```

**Personal Lab Config**

```auto
winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h

  - name: System

  - name: Security
    processors:
      #- drop_event.when.or:
      # - equals.winlog.event_id: 4624
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

  - name: Microsoft-Windows-Sysmon/Operational
    processors:
      - drop_event.when.or: 
          - equals.winlog.event_id: 1
      - script:
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

  - name: Windows PowerShell
    event_id: 400, 403, 600, 800
    processors:
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: Microsoft-Windows-PowerShell/Operational
    event_id: 4103, 4104, 4105, 4106
    processors:
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: ForwardedEvents
    tags: [forwarded]
    processors:
      - script:
          when.equals.winlog.channel: Security
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js
      - script:
          when.equals.winlog.channel: Windows PowerShell
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-PowerShell/Operational
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 20, 2021, 9:21pm UTC](https://discuss.elastic.co/t/winlogbeat-filtering-issue/261695/2 "2021-01-20T21:21:30Z")

</div>

Try using a string in your config rather than a number. IIRC the `winlog.event_id` field is a string in the JSON documents so equality matching probably needs the value to be a string.

```auto
      - drop_event.when.or: 
          - equals.winlog.event_id: '1'

```

Additionally if you want to silence noise from Sysmon, consider using a sysmon XML config file so that it never even collects that particular data. It will save you some CPU cycles and disk space.

---

<div class="post-metadata">

**Author:** ![jcor](https://avatars.discourse-cdn.com/v4/letter/j/8797f3/32.png) [@jcor](https://discuss.elastic.co/u/jcor)\
**Post date:** [January 22, 2021, 3:41pm UTC](https://discuss.elastic.co/t/winlogbeat-filtering-issue/261695/3 "2021-01-22T15:41:03Z")

</div>

So I'll give that a shot next, but do you have any idea why its still sending sysmon if I took out the below config options?

```auto
- name: Microsoft-Windows-Sysmon/Operational
    processors:
      - drop_event.when.or: 
          - equals.winlog.event_id: 1
      - script:
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

```

and

```auto
- script:
          when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 2, 2021, 1:51am UTC](https://discuss.elastic.co/t/winlogbeat-filtering-issue/261695/4 "2021-02-02T01:51:01Z")

</div>

> [@jcor](#):
>
> So I'll give that a shot next, but do you have any idea why its still sending sysmon if I took out the below config options?

If you removed the `winlogbeat.event_logs` entry with `name: Microsoft-Windows-Sysmon/Operational` then it won't read any more Sysmon logs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2021, 3:51am UTC](https://discuss.elastic.co/t/winlogbeat-filtering-issue/261695/5 "2021-03-02T03:51:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
