InTrust Real-Time Collection and Splunk Forward Filter

When you create forward filter to forwarder list of event id’s to SPLUNK, you can say Account Name choose don’t forward anything that ends with $ this will not forward for all event ID’s, but if you want to forward anything that ends with $ for one or two event id in your list. How do you create the filter so it will forwarder everything including anything that ends with $ for that specific event id? I don’t see option in InTrust 11.4.