# Would dropping events by regexp match be possible?

**URL:** <https://discuss.elastic.co/t/would-dropping-events-by-regexp-match-be-possible/212642>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [December 20, 2019, 10:18am UTC](https://discuss.elastic.co/t/would-dropping-events-by-regexp-match-be-possible/212642 "2019-12-20T10:18:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [December 20, 2019, 10:18am UTC](https://discuss.elastic.co/t/would-dropping-events-by-regexp-match-be-possible/212642/1 "2019-12-20T10:18:17Z")

</div>

Any suggestions on how we best would target just below events from our backup client for the purpose of dropping such in winlogbeat?

Could we do a regexp match on event\_data.ProcessName as event.code or event.action might drop too much we fear?

Hints appreciated, TIA!

```
{
  "_index": "siempoc_winlogbeat-7.5.0-2019.12.15",
  "_type": "_doc",
  "_id": "pQ-eCm8BLpqjdLaNYc-Z",
  "_version": 1,
  "_score": null,
  "_source": {
    "@timestamp": "2019-12-15T17:32:36.508Z",
    "agent": {
      "version": "7.5.0",
      "type": "winlogbeat",
      "ephemeral_id": "0bcd4dcf-f906-4bb9-b234-3d37021cbeaa",
      "hostname": "tdchprt03",
      "id": "ed2a3cc9-c384-46af-8aaa-cbddc05d628e"
    },
    "log": {
      "level": "information"
    },
    "message": "The handle to an object was closed.\n\nSubject :\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tTDCHPRT03$\n\tAccount Domain:\t\t<redacted>\n\tLogon ID:\t\t0x3e7\n\nObject:\n\tObject Server:\t\tSecurity\n\tHandle ID:\t\t0xfa0\n\nProcess Information:\n\tProcess ID:\t\t0x83c\n\tProcess Name:\t\tC:\\Program Files\\Tivoli\\TSM\\baclient\\dsmcsvc.exe",
    "winlog": {
      "api": "wineventlog",
      "provider_name": "Microsoft-Windows-Security-Auditing",
      "event_id": 4658,
      "computer_name": "tdchprt03<redacted>",
      "opcode": "Info",
      "record_id": 950353023,
      "task": "File System",
      "keywords": [
        "Audit Success"
      ],
      "provider_guid": "{54849625-5478-4994-a5ba-3e3b0328c30d}",
      "process": {
        "pid": 4,
        "thread": {
          "id": 80
        }
      },
      "event_data": {
        "ObjectServer": "Security",
        "HandleId": "0xfa0",
        "ProcessId": "0x83c",
        "ProcessName": "C:\\Program Files\\Tivoli\\TSM\\baclient\\dsmcsvc.exe",
        "SubjectUserSid": "S-1-5-18",
        "SubjectUserName": "TDCHPRT03$",
        "SubjectDomainName": "<redacted>",
        "SubjectLogonId": "0x3e7"
      },
      "channel": "Security"
    },
    "event": {
      "provider": "Microsoft-Windows-Security-Auditing",
      "action": "File System",
      "created": "2019-12-15T17:32:39.308Z",
      "kind": "event",
      "code": 4658
    },
    "ecs": {
      "version": "1.1.0"
    },
    "host": {
      "name": "tdchprt03",
      "hostname": "tdchprt03",
      "id": "a543946a-cda2-43ba-8b27-a5d91690bec8"
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [December 20, 2019, 10:59am UTC](https://discuss.elastic.co/t/would-dropping-events-by-regexp-match-be-possible/212642/2 "2019-12-20T10:59:06Z")

</div>

assume it would be possible if I just RTFM 😉

Something like this right?

```
processors:
 - drop_event:
     when:
       regexp:
          event_data.ProcessName: ".+\\Tivoli\\TSM\\baclient\\dsmcsvc.exe"
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 20, 2019, 5:29pm UTC](https://discuss.elastic.co/t/would-dropping-events-by-regexp-match-be-possible/212642/3 "2019-12-20T17:29:32Z")

</div>

Yeah, that's pretty common for reducing noise from benign activity. I would however recommend to only use single quotes around regular expressions so that you don't need to escape the contents which often leads to confusion and mistakes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2020, 5:29pm UTC](https://discuss.elastic.co/t/would-dropping-events-by-regexp-match-be-possible/212642/4 "2020-01-17T17:29:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
