# Winlogbeat not filtering event more than 21 sources

**URL:** <https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 19, 2020, 6:55am UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740 "2020-06-19T06:55:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![kumarbn](https://avatars.discourse-cdn.com/v4/letter/k/54ee81/32.png) [@kumarbn](https://discuss.elastic.co/u/kumarbn)\
**Post date:** [June 19, 2020, 6:55am UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740/1 "2020-06-19T06:55:10Z")

</div>

unable to get alert on kafka if we mention more than 21 event source in winlogbeat yml file .

---

<div class="post-metadata">

**Author:** ![mazoutte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mazoutte/32/120188_2.png) [@mazoutte](https://discuss.elastic.co/u/mazoutte)\
**Post date:** [June 19, 2020, 10:57am UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740/2 "2020-06-19T10:57:31Z")

</div>

HELLO

It's documented in the official documentation :  
[https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html)

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 19, 2020, 3:17pm UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740/3 "2020-06-19T15:17:56Z")

</div>

Lol, I also stumbled on this one today. Imho, this should be handled by winlogbeat in the background? Also, the url to the kb in [https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html) doesn't work.  
Grtz

---

<div class="post-metadata">

**Author:** ![kumarbn](https://avatars.discourse-cdn.com/v4/letter/k/54ee81/32.png) [@kumarbn](https://discuss.elastic.co/u/kumarbn)\
**Post date:** [June 22, 2020, 4:40am UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740/4 "2020-06-22T04:40:38Z")

</div>

Hi mazoutte,

Thank you for your replay , I have referred given link but it is not working , winlogbeat filtering alert till if we mention 21 sources under providers, but after 21 sources we are not getting any output on kafka.

---

<div class="post-metadata">

**Author:** ![mazoutte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mazoutte/32/120188_2.png) [@mazoutte](https://discuss.elastic.co/u/mazoutte)\
**Post date:** [June 22, 2020, 8:29am UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740/5 "2020-06-22T08:29:41Z")

</div>

Hello,

Please post your configuration of Winlogbeat to check.

Regarding the documentation, what did you try when you say its not working ?

Copy/Paste of the documentation :

_If you specify more that 22 event IDs to include or 22 event IDs to exclude, Windows will prevent Winlogbeat from reading the event log because it limits the number of conditions that can be used in an event log query. If this occurs a similar warning as shown below will be logged by Winlogbeat, and it will continue processing data from other event logs. For more information, see [https://support.microsoft.com/en-us/kb/970453](https://support.microsoft.com/en-us/kb/970453)._

```
WARN EventLog[Application] Open() error. No events will be read from this
source. The specified query is invalid.

```

_If you have more than 22 event IDs, you can workaround this Windows limitation by using a drop\_event[drop-event] processor to do the filtering after Winlogbeat has received the events from Windows. The filter shown below is equivalent to event\_id: 903, 1024, 4624 but can be expanded beyond 22 event IDs._

```
winlogbeat.event_logs:
  - name: Security
    processors:
      - drop_event.when.not.or:
        - equals.winlog.event_id: 903
        - equals.winlog.event_id: 1024
        - equals.winlog.event_id: 4624
```

---

<div class="post-metadata">

**Author:** ![kumarbn](https://avatars.discourse-cdn.com/v4/letter/k/54ee81/32.png) [@kumarbn](https://discuss.elastic.co/u/kumarbn)\
**Post date:** [June 22, 2020, 8:59am UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740/6 "2020-06-22T08:59:45Z")

</div>

please find configuration below. where I have 50 source and 50 event ID. configuration file is working if i mention 21 sources ..but if I add more source than 21 not getting any alert.

winlogbeat.event\_logs:

- name: Application  
Leval: error, info, warning, critical,  
ignore\_older: 72h

may be am missing something ..please suggest

---

<div class="post-metadata">

**Author:** ![mazoutte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mazoutte/32/120188_2.png) [@mazoutte](https://discuss.elastic.co/u/mazoutte)\
**Post date:** [June 22, 2020, 9:37am UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740/7 "2020-06-22T09:37:03Z")

</div>

Please use the correct format for pasting the config.

Use the same logic as for Event\_ids ....  
So remove the provider section, and use the drop section to filter unwanted provider or keep the ones you want.

```auto
winlogbeat.event_logs:
  - name: Security
    processors:
      - drop_event.when.not.or:
        - equals.winlog.provider_name: source1
        - equals.winlog.provider_name: source2

```

---

<div class="post-metadata">

**Author:** ![kumarbn](https://avatars.discourse-cdn.com/v4/letter/k/54ee81/32.png) [@kumarbn](https://discuss.elastic.co/u/kumarbn)\
**Post date:** [June 22, 2020, 12:00pm UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740/8 "2020-06-22T12:00:52Z")

</div>

Hi [mazoutte](https://discuss.elastic.co/u/mazoutte)

Thank you so much ..it is working.

Please help with filtering alerts with specific message in event. like "system overheating "

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2020, 2:01pm UTC](https://discuss.elastic.co/t/winlogbeat-not-filtering-event-more-than-21-sources/237740/9 "2020-07-20T14:01:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
