I have graylog setup and passing data from my PC to my server using winlogbeats. I am getting all events sent to my server. My question is how to I filter out events I do not want? I do not want all events, I want to exclude events and I have not a clue how.
here is my server.conf
fields: collector_node_id: graylog-collector-sidecar gl2_source_collector: c8053970-6140-438c-babb-11525d7c594a output: logstash: hosts: - 192.168.2.250:5044 path: data: C:\Program Files\graylog\collector-sidecar\cache\winlogbeat\data logs: C:\Program Files\graylog\collector-sidecar\logs tags: - windows - iis winlogbeat: event_logs: - name: Application - name: System - name: Security processors: - drop_event: - when: - equals: - event_id:5152 - event_id:5150 - event_id:5156 - event_id:64