Event ID 5156

The Windows Filtering Platform has allowed a connection.

The Windows Filtering Platform has allowed a connection.

Application Information:

   Process ID:        %1
   Application Name:  %2

Network Information:

   Direction:           %3
   Source Address:      %4
   Source Port:         %5
   Destination Address: %6
   Destination Port:    %7
   Protocol:            %8

Filter Information:

   Filter Run-Time ID:  %9
   Layer Name:          %10
   Layer Run-Time ID:   %11


This event generates when Windows Filtering Platform has allowed a connection.

Note: This event has 13 insertion strings but only 11 are displayed on the general tab.

Auditing:     Rarely

It's only recommended to audit this event if every network connection of a process needs to be tracked.


Volume:     HighVery High

This event is logged for every network connection that is associated with a process, as such the volume of events is generally very high.


Microsoft Documentation

Event ID - 5156



NameFieldInsertion StringOSExample
Process IDProcessID%1Any 4556
Application NameApplication%2Any \device\harddiskvolume2\documents\listener.exe
DirectionDirection%3Any %%14592
Source AddressSourceAddress%4Any 192.168.0.2
Source PortSourcePort%5Any 3333
Destination AddressDestAddress%6Any 192.168.0.1
Destination PortDestPort%7Any 49279
ProtocolProtocol%8Any View Codes
Filter Run-Time IDFilterRTID%9Any 70201
Layer NameLayerName%10Any 14610
Layer Run-Time IDLayerRTID%11Any 44
N/ARemoteUserID%12Any S-1-0-0
N/ARemoteMachineID%13Any S-1-0-0


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Filtering Platform Connection"



LEFT/RIGHT arrow keys for navigation

Back to List