So, I had actually thought about dropping the "equals" and "contains" sections of the fields, as I've seen in other posts, if that's what you're getting at. Our Elastic stack is actually run by a cloud provider and they've mapped their fields in this format, so it works in all other parts of the winlogbeat config with this format.
Winlogbeat runs and all of the other filters work except for this one when it has 3 or more conidtions ANDed together.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.