# Winlogbeat - multiple event\_id's and processor drop\_events

**URL:** <https://discuss.elastic.co/t/winlogbeat-multiple-event-ids-and-processor-drop-events/360392>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 28, 2024, 3:06pm UTC](https://discuss.elastic.co/t/winlogbeat-multiple-event-ids-and-processor-drop-events/360392 "2024-05-28T15:06:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tandav](https://avatars.discourse-cdn.com/v4/letter/t/a698b9/32.png) [@tandav](https://discuss.elastic.co/u/tandav)\
**Post date:** [May 28, 2024, 3:06pm UTC](https://discuss.elastic.co/t/winlogbeat-multiple-event-ids-and-processor-drop-events/360392/1 "2024-05-28T15:06:36Z")

</div>

Running version 7.17.21, but I cannot seem to get this working. What I am trying to do is if event\_id is xxxx than drop event that matches a regex, but if event\_id is not xxxx than drop events that matches a different regex.

```auto
winlogbeat.event_logs:
  - name: security1
    event_id: 4624
    processors:
      - drop_event:
          when:
            regexp:
              message: '^aaaaa|^bbbbb|^ccccc'
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

  - name: security2
    event_id: 4625, 4726, 4740, 4767, 4769
    processors:
       - drop_event:
           when:
             regexp:
               message: '^ddddd|^eeeee|^fffff'
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

```

winlogbeat logs indicate cannot use those names:

```auto
2024-05-28T10:45:43.915-0400	WARN	[winlogbeat]	beater/eventlogger.go:147	Open() encountered channel not found error. Trying again...	{"id": "security2", "error": "The specified channel could not be found.", "channel": "security2"}
2024-05-28T10:45:43.915-0400	WARN	[winlogbeat]	beater/eventlogger.go:147	Open() encountered channel not found error. Trying again...	{"id": "security1", "error": "The specified channel could not be found.", "channel": "security1"}

```

I've also tried, but it doesn't drop anything:

```auto
winlogbeat.event_logs:
  - name: Security
    event_id: 4624, 4625, 4726, 4740, 4767, 4769
    processors:
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - if:
      event.code: 4624
    then:
      - drop_event:
          when:
             regexp:
                message: '^aaaaa|^bbbbb|^ccccc'

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 28, 2024, 3:55pm UTC](https://discuss.elastic.co/t/winlogbeat-multiple-event-ids-and-processor-drop-events/360392/2 "2024-05-28T15:55:15Z")

</div>

Your first attempt is almost correct.

`name` must be the name of an actual event log channel. So it needs to be `Security`. You should add `id` to the configurations to make them unique for persistence on disk.

```yaml
  - id: security1
    name: Security
    event_id: 4624
    ...
  - id: security2
    name: Security
    event_id: 4625, 4726, 4740, 4767, 4769
    ...

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 28, 2024, 4:02pm UTC](https://discuss.elastic.co/t/winlogbeat-multiple-event-ids-and-processor-drop-events/360392/3 "2024-05-28T16:02:08Z")

</div>

> [@tandav](#):
>
> ```auto
> - if:
> event.code: 4624
> 
> ```

That's not a valid config. It errors with

> failed to make if/then/else processor: missing or invalid condition

It's missing the `equals` operator. And the 4624 needs to be string (so add quotes) because the value type in the event is a string ([example](https://github.com/elastic/beats/blob/ba1f1c115316c2434bb0d713bc211d63bc899a14/x-pack/winlogbeat/module/security/test/testdata/1100.evtx.golden.json#L9)).

```yaml
  - if:
      equals:
        event.code: '4624'
    then: ...

```
