It would be nice to have an extended policy set for windows events, for example I would like the LEM to drop event ID 4658 from my exchange servers