Event ID: 4945

A rule was listed when the Windows Firewall started

A rule was listed when the Windows Firewall started.

Profile used:   %1

Rule:
    Rule ID:    %2
    Rule Name:  %3
Microsoft Documentation

Event ID - 4945



This event generates every time Windows Firewall service starts.

This event shows the inbound and/or outbound rule which was listed when the Windows Firewall started and applied for “Public” profile.

This event generates per rule.



Name Field Insertion String OS Example
Profile used ProfileUsed %1 Any Public
Rule ID RuleId %2 Any NPS-NPSSvc-In-RPC
Rule Name RuleName %3 Any Network Policy Server (RPC)


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"MPSSVC Rule-Level Policy Change"
How to enable Windows Auditing



LEFT/RIGHT arrow keys for navigation

Back to List