Can I exclude users from "Attempted to logon using explicit credentials event" or "Account failed to logon event"?

Especially in "Attempted to logon using explicit credentials event" a user needed for a print solution kills the monitoring. I can of course raise thresholds, but then may overlook a real problem.