# Winlogbeat match eventdata param1

**URL:** <https://discuss.elastic.co/t/winlogbeat-match-eventdata-param1/160953>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [December 14, 2018, 6:32pm UTC](https://discuss.elastic.co/t/winlogbeat-match-eventdata-param1/160953 "2018-12-14T18:32:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Siva\_](https://avatars.discourse-cdn.com/v4/letter/s/b5e925/32.png) [@Siva\_](https://discuss.elastic.co/u/Siva_)\
**Post date:** [December 14, 2018, 6:32pm UTC](https://discuss.elastic.co/t/winlogbeat-match-eventdata-param1/160953/1 "2018-12-14T18:32:57Z")

</div>

Hi community,

How can i use the eventdata param1 to filter in winlogbeat?

![image](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6ec3b8a56f4683487c4963e056f57fd2b2c9df55.png)

currently, I am using regex on the message but hoping to avoid it for performance.

```
processors:
- drop_event:
   when:
    not:
     regexp:
      message: "The Citrix Universal Printing Service*"
```

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [December 15, 2018, 3:15am UTC](https://discuss.elastic.co/t/winlogbeat-match-eventdata-param1/160953/2 "2018-12-15T03:15:07Z")

</div>

This is the field name that contains the data in param1: event\_data.param1

---

<div class="post-metadata">

**Author:** ![Siva\_](https://avatars.discourse-cdn.com/v4/letter/s/b5e925/32.png) [@Siva\_](https://discuss.elastic.co/u/Siva_)\
**Post date:** [December 16, 2018, 2:44am UTC](https://discuss.elastic.co/t/winlogbeat-match-eventdata-param1/160953/3 "2018-12-16T02:44:37Z")

</div>

> [@Siva\_](#):
>
> Citrix Universal Printing Service

Thank you!

```
winlogbeat.event_logs:
  - name: System
    provider:
        - Service Control Manager
    event_id: 7036, 7031
    tags: ["citrix","ups"]  
    ignore_older: 5m
    processors:
    - drop_event:
       when:
        not:
         equals:
          event_data.param1: "Citrix Universal Printing Service"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2019, 2:44am UTC](https://discuss.elastic.co/t/winlogbeat-match-eventdata-param1/160953/4 "2019-01-13T02:44:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
