So far the CoreProtectPreLogEvent only has a user string and (optionally) a location of where the log happened. In order to properly make use of the event for filtering logs (which is it's intended use I think) you'd need some more information about what is being logged.