# Winlogbeat removes the event\_id of - 4624 and - 4634 in event\_logs, but it is still collected when kibana queries data. What else do you need to set up?

**URL:** <https://discuss.elastic.co/t/winlogbeat-removes-the-event-id-of-4624-and-4634-in-event-logs-but-it-is-still-collected-when-kibana-queries-data-what-else-do-you-need-to-set-up/165160>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 22, 2019, 6:29am UTC](https://discuss.elastic.co/t/winlogbeat-removes-the-event-id-of-4624-and-4634-in-event-logs-but-it-is-still-collected-when-kibana-queries-data-what-else-do-you-need-to-set-up/165160 "2019-01-22T06:29:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![96470621](https://avatars.discourse-cdn.com/v4/letter/9/51bf81/32.png) [@96470621](https://discuss.elastic.co/u/96470621)\
**Post date:** [January 22, 2019, 6:29am UTC](https://discuss.elastic.co/t/winlogbeat-removes-the-event-id-of-4624-and-4634-in-event-logs-but-it-is-still-collected-when-kibana-queries-data-what-else-do-you-need-to-set-up/165160/1 "2019-01-22T06:29:24Z")

</div>

![kibana](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bd2b9897641a169d2589d7cedf03613e7fa82be4.png)  
 ![winlogbeat](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a0780f2c82ef85366f90742bf7bd91e8834026dd.png)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 27, 2019, 3:40pm UTC](https://discuss.elastic.co/t/winlogbeat-removes-the-event-id-of-4624-and-4634-in-event-logs-but-it-is-still-collected-when-kibana-queries-data-what-else-do-you-need-to-set-up/165160/2 "2019-01-27T15:40:20Z")

</div>

When you configure `event_id: -4624, -4634` this should causes Windows to suppress those two security events in the stream it gives to Winlogbeat. It does this by passing an XML query to the Windows API that says which events to ignore. You can check this XML query by enabling debug logging in the config file.

```auto
logging.level: debug
logging.selectors: [eventlog]

```

At startup you'll see the query in the log file output. It should be similar to:

```auto
<QueryList>
  <Query Id="0">
    <Select Path="Security">*</Select>
    <Suppress Path="Security">*[System[((EventID=4624 or EventID=4634))]]</Suppress>
  </Query>
</QueryList>

```

You can test that XML query using the Windows Event Viewer. Create a custom view and paste the query from the log file to the tab labeled "XML". See an example at [https://blogs.technet.microsoft.com/askds/2011/09/26/advanced-xml-filtering-in-the-windows-event-viewer/](https://blogs.technet.microsoft.com/askds/2011/09/26/advanced-xml-filtering-in-the-windows-event-viewer/). Then check to see if 4624 and 4634 are filtered from the custom view.

If you have multiple Winlogbeat instances running double check that they are all setup to filter out these event IDs.

Another option for filtering events is to use a [drop\_event](https://www.elastic.co/guide/en/beats/winlogbeat/6.5/drop-event.html) processor.

```auto
processors:
  - drop_event:
      when:
        or: 
          - equals.event_id: 4624
          - equals.event_id: 4634

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2019, 3:40pm UTC](https://discuss.elastic.co/t/winlogbeat-removes-the-event-id-of-4624-and-4634-in-event-logs-but-it-is-still-collected-when-kibana-queries-data-what-else-do-you-need-to-set-up/165160/3 "2019-02-24T15:40:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
