Hi,
If you are using event forwarding to make the Windows servers to log to a SIEM using WinRM, you can define which events should be forwarded using the filter dialog in Event Viewer or with the XML query you see above for more advanced filters.
https://serverfault.com/questions/913015/where-are-windows-event-forwarding-wef-subscriptions-filters-applied
However the suppress statements which filter out specific events, only apply within that query statement and are not to the entire subscription.
https://learn.microsoft.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection#baseline-subscription
Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.
Thanks,
Jenny