Details are in https://github.com/elastic/integrations/issues/3147 Implement ignore_older for the following event logs: - Forwarded - Powershell - Powershell Operational - System Operational