Policies decide which normalised events are forwarded and to which destinations. A policy is a positive selector: an event that matches an enabled policy is sent to that policy's destinations.

any (the event matches if it satisfies at least one criterion) or all (it must satisfy every criterion).identity, privileged, logins).authentication, user_group_mgmt).Click New policy (or a policy's name) to open the editor. Fill in the criteria, pick the destinations and click Apply.

Think of policies as the "allow-list" of your forwarding pipeline: nothing is shipped unless a policy (or a route) selects it. Combine a broad policy with exclusions to remove the few noisy event types you do not want.