System32
Events
Compliance
Validator
TLS/SSL
PingSentry
GeoIP
Tools
Audit Category
Policy Change
(40)
Audit Subcategory
Filtering Platform Policy Change
(40)
Operating Systems
Windows 10
(40)
Windows 2008
(40)
Windows 2008 R2
(40)
Windows 2012
(40)
Windows 2012 R2
(40)
Windows 2016
(40)
Windows 2019
(40)
Windows 7
(40)
Windows 8
(40)
Windows 8.1
(40)
Windows Vista
(40)
Windows 2022
(39)
Windows 11
(35)
Tags
Auditing
Volume
EventSentry
All events
ID
Event Description
4709
The IPsec Policy Agent service was started
4710
The IPsec Policy Agent service was disabled
4711
PAStore Engine
4712
IPsec Policy Agent encountered a potentially serious failure
5040
A change was made to IPsec settings. An authentication set was added.
5041
A change was made to IPsec settings. An authentication set was modified.
5042
A change was made to IPsec settings. An authentication set was deleted.
5043
A change was made to IPsec settings. A connection security rule was added.
5044
A change was made to IPsec settings. A connection security rule was modified.
5045
A change was made to IPsec settings. A connection security rule was deleted.
5046
A change was made to IPsec settings. A crypto set was added.
5047
A change was made to IPsec settings. A crypto set was modified.
5048
A change was made to IPsec settings. A crypto set was deleted.
5440
The following callout was present when the Windows Filtering Platform Base Filtering Engine started.
5441
The following filter was present when the Windows Filtering Platform Base Filtering Engine started.
5442
The following provider was present when the Windows Filtering Platform Base Filtering Engine started.
5443
The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.
5444
The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started.
5446
A Windows Filtering Platform callout has been changed.
5448
A Windows Filtering Platform provider has been changed.
5449
A Windows Filtering Platform provider context has been changed.
5450
A Windows Filtering Platform sub-layer has been changed.
5456
IPsec Policy Agent applied Active Directory storage IPsec policy on the computer.
5457
IPsec Policy Agent failed to apply Active Directory storage IPsec policy on the computer.
5458
IPsec Policy Agent applied locally cached copy of Active Directory storage IPsec policy on the computer.
5459
IPsec Policy Agent failed to apply locally cached copy of Active Directory storage IPsec policy on the computer.
5460
IPsec Policy Agent applied local registry storage IPsec policy on the computer.
5461
IPsec Policy Agent failed to apply local registry storage IPsec policy on the computer
5462
IPsec Policy Agent failed to apply some rules of the active IPsec policy on the computer.
5463
IPsec Policy Agent polled for changes to the active IPsec policy and detected no changes.
5464
IPsec Policy Agent polled for changes to the active IPsec policy, detected changes, and applied them.
5465
IPsec Policy Agent received a control for forced reloading of IPsec policy and processed the control successfully.
5466
IPsec Policy Agent polled for changes to the Active Directory IPsec policy.
5467
IPsec Policy Agent polled for changes to the Active Directory IPsec policy.
5468
IPsec Policy Agent polled for changes to the Active Directory IPsec policy.
5471
IPsec Policy Agent loaded local storage IPsec policy on the computer.
5472
IPsec Policy Agent failed to load local storage IPsec policy on the computer.
5473
IPsec Policy Agent loaded directory storage IPsec policy on the computer.
5474
IPsec Policy Agent failed to load directory storage IPsec policy on the computer.
5477
IPsec Policy Agent failed to add quick mode filter.