# Winlogbeat not dropping multicast traffic using drop\_event.when.or

**URL:** <https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [December 22, 2020, 9:29pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428 "2020-12-22T21:29:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jtillman2020](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jtillman2020](https://discuss.elastic.co/u/jtillman2020)\
**Post date:** [December 22, 2020, 9:29pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428/1 "2020-12-22T21:29:03Z")

</div>

Using drop\_event.when.or I've attempted to exclude multicast traffic logs from being sent over as well as logs containing the keyword "zabbix". However, I am still receiving these events.

```auto
winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h

  - name: System
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - drop_event.when.or:
        - contains.event_data: "224.0.0" #Drop multicast traffic
        - contains.event_data: "239.255.255.250" #Drop multicast traffic
        - contains.event_data: "zabbix" #Drop zabbix traffic

  - name: Security
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - drop_event.when.or:
        - contains.event_data: "224.0.0" #Drop multicast traffic
        - contains.event_data: "239.255.255.250" #Drop multicast traffic
        - contains.event_data: "zabbix" #Drop zabbix traffic
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

  - name: Microsoft-Windows-Sysmon/Operational
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - script:
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

  - name: Windows PowerShell
    event_id: 400, 403, 600, 800
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: Microsoft-Windows-PowerShell/Operational
    event_id: 4103, 4104, 4105, 4106
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: ForwardedEvents
    tags: [forwarded]
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - script:
          when.equals.winlog.channel: Security
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js
      - script:
          when.equals.winlog.channel: Windows PowerShell
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-PowerShell/Operational
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

```

---

<div class="post-metadata">

**Author:** ![jtillman2020](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jtillman2020](https://discuss.elastic.co/u/jtillman2020)\
**Post date:** [December 22, 2020, 9:56pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428/2 "2020-12-22T21:56:41Z")

</div>

I changed the field to winlog.event\_data for the security log just to test and still no luck:

```auto
winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h

  - name: System
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - drop_event.when.or:
        - contains.winlog.event_data: "224.0.0" #Drop multicast traffic
        - contains.winlog.event_data: "239.255.255.250" #Drop multicast traffic
        - contains.winlog.event_data: "zabbix" #Drop zabbix traffic

  - name: Security
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - drop_event.when.or:
        - contains.winlog.event_data: "224.0.0" #Drop multicast traffic
        - contains.winlog.event_data: "239.255.255.250" #Drop multicast traffic
        - contains.winlog.event_data: "zabbix" #Drop zabbix traffic
      - script:
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js

  - name: Microsoft-Windows-Sysmon/Operational
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - drop_event.when.or:
        - contains.event_data: "224.0.0" #Drop multicast traffic
        - contains.event_data: "239.255.255.250" #Drop multicast traffic
        - contains.event_data: "zabbix" #Drop zabbix traffic
      - script:
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

  - name: Windows PowerShell
    event_id: 400, 403, 600, 800
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: Microsoft-Windows-PowerShell/Operational
    event_id: 4103, 4104, 4105, 4106
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - script:
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

  - name: ForwardedEvents
    tags: [forwarded]
    processors:
      - drop_fields:
          fields: [winlog.provider_guid, winlog.process.pid, winlog.process.thread.id, winlog.version, winlog.event_data.ErrorSourceTable]
      - script:
          when.equals.winlog.channel: Security
          lang: javascript
          id: security
          file: ${path.home}/module/security/config/winlogbeat-security.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational
          lang: javascript
          id: sysmon
          file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js
      - script:
          when.equals.winlog.channel: Windows PowerShell
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js
      - script:
          when.equals.winlog.channel: Microsoft-Windows-PowerShell/Operational
          lang: javascript
          id: powershell
          file: ${path.home}/module/powershell/config/winlogbeat-powershell.js

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 23, 2020, 1:13pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428/3 "2020-12-23T13:13:43Z")

</div>

> [@jtillman2020](#):
>
> `contains.winlog.event_data`

This won't match because [`contains`](https://www.elastic.co/guide/en/beats/winlogbeat/current/defining-processors.html#condition-contains) acts like a substring match and `event_data` is an object. If you can change event\_data to a leaf field that contains a string like `winlog.event_data.IpAddress` things will work better.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 23, 2020, 1:26pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428/4 "2020-12-23T13:26:02Z")

</div>

And BTW there is a condition for matching network addresses. See [https://www.elastic.co/guide/en/beats/winlogbeat/7.7/defining-processors.html#condition-network](https://www.elastic.co/guide/en/beats/winlogbeat/7.7/defining-processors.html#condition-network).

```auto
- drop_event:
    when.network:
      winlog.event_data.IpAddress: [multicast]

```

---

<div class="post-metadata">

**Author:** ![jtillman2020](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jtillman2020](https://discuss.elastic.co/u/jtillman2020)\
**Post date:** [December 23, 2020, 3:29pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428/5 "2020-12-23T15:29:13Z")

</div>

Thanks for your reply Andrew. I thought about it some last night and came to that conclusion so I modified the line to:

```auto
processors:
      - drop_event.when.or:
          - equals.event_data.ProcessName: "zabbix_agentd.exe"

```

This was after looking in Kibana to find ProcessName:

```auto
Dec 22, 2020 @ 22:55:43.566

process_name:
    zabbix_agentd.exe
opcode:
    Info
level:
    information
src_ip_rfc:
    RFC_1918
 .......

```

Unfortunately this did not work either. I tried modifying it to equals.winlog.event\_data.ProcessName with no luck.

---

<div class="post-metadata">

**Author:** ![jtillman2020](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jtillman2020](https://discuss.elastic.co/u/jtillman2020)\
**Post date:** [December 23, 2020, 5:23pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428/6 "2020-12-23T17:23:02Z")

</div>

I also tried this one and had no luck with filtering out multicast:

```auto
    #-------------------------- Windows Logs To Collect -----------------------------
    winlogbeat.event_logs:
      - name: Application
        ignore_older: 30m
      - name: Security
        ignore_older: 30m
        processors:
          - drop_event:
              when.network:
                winlog.event_data.IpAddress: [multicast]
      - name: System
        ignore_older: 30m
      - name: Microsoft-windows-sysmon/operational
        ignore_older: 30m
      - name: Microsoft-windows-PowerShell/Operational
        ignore_older: 30m
        event_id: 4103, 4104
      - name: Windows PowerShell
        event_id: 400,600
        ignore_older: 30m
      - name: Microsoft-Windows-WMI-Activity/Operational
        event_id: 5857,5858,5859,5860,5861

```

This was received a few minutes after making the change and restarting the winlogbeat service.

```auto
    event_original_message	
    The Windows Filtering Platform has permitted a connection.

    Application Information:
    	Process ID: 884
    	Application Name:	\device\harddiskvolume2\windows\system32\svchost.exe

    Network Information:
    	Direction: Inbound
    	Source Address: 224.0.0.252
    	Source Port: 5355
    	Destination Address:	10.0.0.188
    	Destination Port: 62098
    	Protocol: 17

    Filter Information:
    	Filter Run-Time ID:	0
    	Layer Name: Receive/Accept
    	Layer Run-Time ID:	44
    event_original_time	
    2020-12-23T17:21:30.156Z
    keywords	Audit Success
    level	information
    log_name	Security

```

---

<div class="post-metadata">

**Author:** ![jtillman2020](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jtillman2020](https://discuss.elastic.co/u/jtillman2020)\
**Post date:** [December 23, 2020, 5:58pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428/7 "2020-12-23T17:58:40Z")

</div>

This worked. Guess I have to do another one for DestinationAddress? Still unable to filter the zabbix events unfortunately. Tried filtering it based on source port and it did not work.

```auto
processors:
  - drop_event.when.or:
      - network:
          winlog.event_data.SourceAddress: [multicast]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 20, 2021, 7:58pm UTC](https://discuss.elastic.co/t/winlogbeat-not-dropping-multicast-traffic-using-drop-event-when-or/259428/8 "2021-01-20T19:58:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
