Customization of alerts through allow-list members is only supported in standard alerts defined in the manual:
PCI related alerts 1209, 1210, and 1211
Sensitive data sets, members and resources 1204, 1212, 1213, and 1214
and their equivalent ACF2 alerts.
Alerts are generated from SMF, system log, access monitor and configuration information using a CARLa script. The script is generated by the V line command in ISPF option SE.A.A from skeleton members. The select and exclude functions (filters, in your question) are semi-hardcoded in the skeletons. You cannot add filters to standard alerts, unless you edit the corresponding skeleton members, and that would break support for these IBM-maintained members.
You can copy the concept of these alerts into your own installation defined alerts, of course, thus using the same allow-lists.
For other fields, as Rene described, you have the CARLa field reference for SMF types. You can use these in the installation defined alerts that you build as a copy of standard alerts. Filters on those other fields are not available in standard alerts.
------------------------------
Rob van Hoboken
------------------------------