Create a filter and include the event ID at the windows agent to drop them at that point.
The Source and Event ID would be the optimal filter to use. Additionally the event itself should show the source you need to set as well.
This section of the documentations shows how to do that.
https://support.oneidentity.com/technical-documents/syslog-ng-premium-edition/6.0.14/administrator-guide-for-syslog-ng-agent-for-windows/4#TOPIC-1085241
Syslog-ng Agent puts the the event id in the message, like this:
"(EventID 4672)"