I want to drop events if provider is not Service Control Manager or mfehidk or PRIVMAN AND if event_id is not 7036 or 516 or 100.
However this doesnot seems to work i am getting events that should be blocked? Any suggestions??
winlogbeat: event_logs: - name: System provider: - Service Control Manager - mfehidk - PRIVMAN processors: - drop_event.when: - not.or: - equals.event_id: 7036 - equals.event_id: 516 - equals.event_id: 100