Event ID 4945

A rule was listed when the Windows Firewall started

A rule was listed when the Windows Firewall started.

Profile used:   %1

Rule:
    Rule ID:    %2
    Rule Name:  %3


This event generates every time Windows Firewall service starts.

This event shows the inbound and/or outbound rule which was listed when the Windows Firewall started and applied for the “Public” profile. Unfortunately this event only ever shows rules for the Public profile.

This event generates per rule.

Auditing:     Always


Volume:     Low


Microsoft Documentation

Event ID - 4945



Name Field Insertion String OS Example
Profile used ProfileUsed %1 Any Public
Rule ID RuleId %2 Any NPS-NPSSvc-In-RPC
Rule Name RuleName %3 Any Network Policy Server (RPC)


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"MPSSVC Rule-Level Policy Change"



LEFT/RIGHT arrow keys for navigation

Back to List