https://www.oryszczyn.com/filtering-events-on-the-microsoft-ama-syslog-agent-for-sentinel/
Filtering Events on the Microsoft AMA Syslog Agent for Microsoft Sentinel