# Winlogbeat - Need Help with Drop\_fields

**URL:** <https://discuss.elastic.co/t/winlogbeat-need-help-with-drop-fields/291926>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [December 15, 2021, 8:47am UTC](https://discuss.elastic.co/t/winlogbeat-need-help-with-drop-fields/291926 "2021-12-15T08:47:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![0xf](https://avatars.discourse-cdn.com/v4/letter/0/e47774/32.png) [@0xf](https://discuss.elastic.co/u/0xf)\
**Post date:** [December 15, 2021, 8:47am UTC](https://discuss.elastic.co/t/winlogbeat-need-help-with-drop-fields/291926/1 "2021-12-15T08:47:25Z")

</div>

So basically what i would like to do is drop everything from the fields and manually include a few.  
So to say, i want to drop every field that im not putting/specifying in this config file.

In this case i tried to specifiy and tie it to 4624 and 4625 event id.

But also my second problem is that "drop\_fields" doesnt seem to work at all. Even when i try to drop only a specific field.

```auto
- name: Security
    event_id: 4624, 4625
    ignore_older:
    processors:
      - drop_event.when.or:
        - and:
          - equals.winlog.event_id: 4624
          - or:
            # Exclude these conditions from Event ID 4624
            - equals.winlog.event_data.TargetUserName": 'SYSTEM'
            - equals.winlog.event_data.SubjectUserSid: 'S-1-0-0'
        - and:
          - equals.winlog.event_id: 4625
          - or:
            # Exclude these conditions from Event ID 4625
            - equals.winlog.event_data.TargetUserSid: 'S-1-5-18'
            - equals.winlog.event_data.TargetUserName: 'SYSTEM'
      - drop_fields:
          fields: ["winlog.channel", "winlog.event_data.IpAddress", "winlog.event_data.IpPort", "winlog.event_data.LogonProcessName", "winlog.event_data.ProcessName", "winlog.event_data.SubjectDomainName", "winlog.event_data.TargetUserName", "winlog.event_data.TargetUserSid"]
          when.not.or:
              - equals.winlog.event_id: 4624
              - equals.winlog.event_id: 4625

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 16, 2021, 12:32am UTC](https://discuss.elastic.co/t/winlogbeat-need-help-with-drop-fields/291926/2 "2021-12-16T00:32:33Z")

</div>

I think you need to quote the numbers to make them a string. And I would add `ignore_missing: true` to the drop\_fields.

```auto
processors:
- drop_event.when.or:
  - and:
    - equals.winlog.event_id: '4624'
    - or:
      - equals.winlog.event_data.TargetUserName: SYSTEM
      - equals.winlog.event_data.SubjectUserSid: S-1-0-0
  - and:
    - equals.winlog.event_id: '4625'
    - or:
      - equals.winlog.event_data.TargetUserSid: S-1-5-18
      - equals.winlog.event_data.TargetUserName: SYSTEM
- drop_fields:
    fields:
    - winlog.channel
    - winlog.event_data.IpAddress
    - winlog.event_data.IpPort
    - winlog.event_data.LogonProcessName
    - winlog.event_data.ProcessName
    - winlog.event_data.SubjectDomainName
    - winlog.event_data.TargetUserName
    - winlog.event_data.TargetUserSid
    ignore_missing: true
    when.not.or:
    - equals.winlog.event_id: '4624'
    - equals.winlog.event_id: '4625'

```

---

<div class="post-metadata">

**Author:** ![0xf](https://avatars.discourse-cdn.com/v4/letter/0/e47774/32.png) [@0xf](https://discuss.elastic.co/u/0xf)\
**Post date:** [December 16, 2021, 3:03pm UTC](https://discuss.elastic.co/t/winlogbeat-need-help-with-drop-fields/291926/3 "2021-12-16T15:03:10Z")

</div>

It doesn't seems to take effect. I still see the old fields appearing in Kibana.

Also i noticed at the end.

```auto
    when.not.or:
    - equals.winlog.event_id: '4624'
    - equals.winlog.event_id: '4625'

```

So here we basically exclude event 4624 and 4625. Problem is here that i actually want specify what fields i keep in 4624 and 4625.

Also, when i run this here, its only dropping these specific fields. I would like to keep, so if its not matching with these drop the other fields, if it matches i want to keep them

```auto
- drop_fields:
    fields:
    - winlog.channel
    - winlog.event_data.IpAddress
    - winlog.event_data.IpPort
    - winlog.event_data.LogonProcessName
    - winlog.event_data.ProcessName
    - winlog.event_data.SubjectDomainName
    - winlog.event_data.TargetUserName
    - winlog.event_data.TargetUserSid
    ignore_missing: true

```

Can i do something that specifies 4624 and 4625 where i can include fields manually and drop all the others?

I really would like to drop every "winlog" field and then specify which i want to keep. Its not an option for me to exclude field one by one.

---

<div class="post-metadata">

**Author:** ![0xf](https://avatars.discourse-cdn.com/v4/letter/0/e47774/32.png) [@0xf](https://discuss.elastic.co/u/0xf)\
**Post date:** [December 17, 2021, 1:41pm UTC](https://discuss.elastic.co/t/winlogbeat-need-help-with-drop-fields/291926/4 "2021-12-17T13:41:15Z")

</div>

I think i solved my problem. With this everything else drops but the specified fields not.

It was easier to use the following:

```auto
    processors:
      - include_fields:
          fields: ["winlog.channel", "winlog.event_data.IpAddress", "winlog.event_data.IpPort", "winlog.event_data.LogonProcessName", "winlog.event_data.ProcessName", "winlog.event_data.SubjectDomainName", "winlog.event_data.TargetUserName", "winlog.event_data.TargetUserSid"]

```

So i tie this to the type of the log source for example 'System' or 'Security':

```auto
- name: System
    ignore_older:
    event_id: 7036
    processors:
      - include_fields:
          fields: ["winlog.event_id", "winlog.channel", "winlog.event_data.param1", "winlog.event_data.param2"]

```

```auto
- name: Security
    ignore_older:
    event_id: 2
    processors:
      - include_fields:
          fields: ["winlog.event_id", "winlog.channel", "winlog.event_data.param1", "winlog.event_data.param2"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2022, 3:42pm UTC](https://discuss.elastic.co/t/winlogbeat-need-help-with-drop-fields/291926/5 "2022-01-14T15:42:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
