# Winlogbeat processor not dropping events

**URL:** <https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 16, 2018, 5:45am UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634 "2018-01-16T05:45:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![saikrishnagaddipati](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@saikrishnagaddipati](https://discuss.elastic.co/u/saikrishnagaddipati)\
**Post date:** [January 16, 2018, 5:45am UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634/1 "2018-01-16T05:45:44Z")

</div>

I want to drop events if provider is not Service Control Manager or mfehidk or PRIVMAN AND if event\_id is not 7036 or 516 or 100.  
However this doesnot seems to work i am getting events that should be blocked? Any suggestions??

```auto
winlogbeat:
  event_logs:
  - name: System
    provider:
    - Service Control Manager
    - mfehidk
    - PRIVMAN
  processors:
  - drop_event.when:
      - not.or: 
         - equals.event_id: 7036
         - equals.event_id: 516
         - equals.event_id: 100

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 16, 2018, 7:01pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634/2 "2018-01-16T19:01:53Z")

</div>

The processors are not being configured because the `processors` configuration option is specified at an invalid location. Currently you have it indented such that it is a sibling of `event_logs`, but it needs to be either a sibling of `winlogbeat` for global usage or a sibling of `name` and `provider` for a local processor (local support added in 6.x). Specifying them with the event\_log they operate on is best for performance.

What version of Winlogbeat are you using?

```auto
winlogbeat.event_logs:
- name: System
  provider:
  - Service Control Manager
  - mfehidk
  - PRIVMAN
  processors:
  - drop_event.when.not.or: 
    - equals.event_id: 7036
    - equals.event_id: 516 
    - equals.event_id: 100 

```

If you enable debug logging (`-e -d "processors"`) you will see logs like:

```auto
2018/01/16 18:56:22.772468 condition.go:97: DBG [processors] New condition equals: map[event_id:7036]
2018/01/16 18:56:22.772479 condition.go:97: DBG [processors] New condition equals: map[event_id:516]
2018/01/16 18:56:22.772488 condition.go:97: DBG [processors] New condition equals: map[event_id:100]
2018/01/16 18:56:22.772496 condition.go:97: DBG [processors] New condition equals: map[event_id:7036] or equals: map[event_id:516] or equals: map[event_id:100]
2018/01/16 18:56:22.772506 condition.go:97: DBG [processors] New condition not equals: map[event_id:7036] or equals: map[event_id:516] or equals: map[event_id:100]
2018/01/16 18:56:22.772519 processor.go:49: DBG [processors] Processors: drop_event, condition=not equals: map[event_id:7036] or equals: map[event_id:516] or equals: map[event_id:100]

```

---

<div class="post-metadata">

**Author:** ![saikrishnagaddipati](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@saikrishnagaddipati](https://discuss.elastic.co/u/saikrishnagaddipati)\
**Post date:** [January 16, 2018, 8:08pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634/3 "2018-01-16T20:08:18Z")

</div>

Hi @andrewkroh, appreciate your quick reply  
I am using winlogbeat-5.6.3 version.  
I tried your config but got the below error

2018-01-16T12:18:56-07:00 CRIT Exiting: Failed to create new event log. 1 error: Invalid event log key 'processors' found. Valid keys are api, batch\_read\_size, event\_id, fields, fields\_under\_root, forwarded, ignore\_older, include\_xml, level, name, provider, tags

But when i make processors a sibling of winlogbeat as below its working  
winlogbeat.event\_logs:  
- name: System  
provider:  
- Service Control Manager  
- mfehidk  
- PRIVMAN  
- test  
processors:  
- drop\_event.when.not.or:  
- equals.event\_id: 7036  
- equals.event\_id: 516  
- equals.event\_id: 100  
- equals.event\_id: 555

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 16, 2018, 8:20pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634/4 "2018-01-16T20:20:30Z")

</div>

Like I said, this configuration is only supported in 6.x.

> [@andrewkroh](#):
>
> sibling of name and provider for a local processor (local support added in 6.x).

You'll need to use a global processor configuration because you are not using 6.x.

```auto
winlogbeat.event_logs:
- name: System
  provider:
  - Service Control Manager
  - mfehidk
  - PRIVMAN

processors:
- drop_event.when.not.or: 
  - equals.event_id: 7036
  - equals.event_id: 516 
  - equals.event_id: 100 

```

---

<div class="post-metadata">

**Author:** ![saikrishnagaddipati](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@saikrishnagaddipati](https://discuss.elastic.co/u/saikrishnagaddipati)\
**Post date:** [January 16, 2018, 8:53pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634/5 "2018-01-16T20:53:26Z")

</div>

thankyou @andrewkroh

---

<div class="post-metadata">

**Author:** ![grants](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grants/32/117040_2.png) [@grants](https://discuss.elastic.co/u/grants)\
**Post date:** [January 23, 2018, 5:08pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634/6 "2018-01-23T17:08:41Z")

</div>

```
PS C:\Apps\winlogbeat-6.1.2-windows-x86_64> .\winlogbeat.exe
Exiting: Failed to create new event log. 1 error: Invalid event log key 'processors' found. Valid keys are api, batch_read_size, event_id, fields, fields_under_root, forwarded, ignore_older, include_xml, level, name, provider, tags

```

I have tried sticking processors all over the place in winlogbeat section and haven't gotten it to work yet besides in the global section, better documentation is needed for 6.x+.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 23, 2018, 5:25pm UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634/7 "2018-01-23T17:25:02Z")

</div>

Sounds like you have hit a config validation bug in 6.x. The `processors` key is missing from the list in that error message. Until that's addresseed only processors at the top-level will work.

I believe `processors` should be included in the list at:

> <https://github.com/elastic/beats/blob/master/winlogbeat/eventlog/factory.go#L13>

Can you please open an issue for this on Github.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 30, 2018, 3:49am UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634/8 "2018-01-30T03:49:51Z")

</div>

> <https://github.com/elastic/beats/pull/6217>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2018, 3:50am UTC](https://discuss.elastic.co/t/winlogbeat-processor-not-dropping-events/115634/9 "2018-02-27T03:50:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
