Log forwarding filtration

We are using the Insight Agent and want to forward only specific Windows Security Event IDs from our servers, specifically:

  • 4720 – User account created

  • 4660 – Object deleted

  • 4732 – Member added to a privileged group

  • 4726 – User account deleted

    how to do this