# Winlogbeat inop filter with more than 2 lines

**URL:** <https://discuss.elastic.co/t/winlogbeat-inop-filter-with-more-than-2-lines/268271>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 24, 2021, 10:15pm UTC](https://discuss.elastic.co/t/winlogbeat-inop-filter-with-more-than-2-lines/268271 "2021-03-24T22:15:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![KStJ](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@KStJ](https://discuss.elastic.co/u/KStJ)\
**Post date:** [March 24, 2021, 10:15pm UTC](https://discuss.elastic.co/t/winlogbeat-inop-filter-with-more-than-2-lines/268271/1 "2021-03-24T22:15:10Z")

</div>

Trying to get Winlogbeat to drop logs matching machine account with impersonation level "%%1833" and logon types 3/4.

Winlogbeat will run, but ignore the processor if I have more than 2 conditions. We are running version 7.9.3.

So, this works and the filter is processed:

- drop\_event.when.and:
  - equals.winlog.event\_data.ImpersonationLevel: "%%1833" #
  - contains.user.name: "$" #Drop Machine Accounts

Winlogbeat runs, but in this version, the filter is ignored:

- drop\_event.when.and:
  - equals.winlog.event\_id: 4624
  - equals.winlog.event\_data.ImpersonationLevel: "%%1833"
  - equals.winlog.event\_data.Logontype: "3"
  - contains.user.name: "$" #Drop Machine Accounts

Does anyone know if this is expected behavior? Is there some sort of limit to the number of conditions in a processor?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 30, 2021, 2:09pm UTC](https://discuss.elastic.co/t/winlogbeat-inop-filter-with-more-than-2-lines/268271/2 "2021-03-30T14:09:46Z")

</div>

I see you have `winlog.event_data.Logontype`, but I think the field is `winlog.event_data.LogonType` like as seen in [4624(S) An account was successfully logged on. (Windows 10) - Windows security | Microsoft Docs](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624).

---

<div class="post-metadata">

**Author:** ![KStJ](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@KStJ](https://discuss.elastic.co/u/KStJ)\
**Post date:** [April 5, 2021, 9:34pm UTC](https://discuss.elastic.co/t/winlogbeat-inop-filter-with-more-than-2-lines/268271/3 "2021-04-05T21:34:01Z")

</div>

Hey, thanks for the reply!

So, I had actually thought about dropping the "equals" and "contains" sections of the fields, as I've seen in other posts, if that's what you're getting at. Our Elastic stack is actually run by a cloud provider and they've mapped their fields in this format, so it works in all other parts of the winlogbeat config with this format.

Winlogbeat runs and all of the other filters work except for this one when it has 3 or more conidtions ANDed together.

---

<div class="post-metadata">

**Author:** ![KStJ](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@KStJ](https://discuss.elastic.co/u/KStJ)\
**Post date:** [April 5, 2021, 9:35pm UTC](https://discuss.elastic.co/t/winlogbeat-inop-filter-with-more-than-2-lines/268271/4 "2021-04-05T21:35:20Z")

</div>

Today, we had the provider filter in their Logstash, which works. Now, I'm just curious as to the behavior of Winlogbeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2021, 11:35pm UTC](https://discuss.elastic.co/t/winlogbeat-inop-filter-with-more-than-2-lines/268271/5 "2021-05-03T23:35:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
