Event ID 5447

A Windows Filtering Platform filter has been changed.

A Windows Filtering Platform filter has been changed.

Subject:
    Security ID:   %2
    Account Name:  %3

Process Information:
    Process ID:    %1

Provider Information:
    ID:            %4
    Name:          %5

Change Information:
    Change Type:   %6

Filter Information:
    ID:            %7
    Name:          %8
    Type:          %9
    Run-Time ID:   %10

Layer Information:
    ID:            %11
    Name:          %12
    Run-Time ID:   %13

Callout Information:
    ID:            %17
    Name:          %18

Additional Information:
    Weight:        %14  
    Conditions:    %15
    Filter Action: %16


This event generates every time a Windows Filtering Platform filter has been changed. It typically generates during Group Policy update procedures.

Auditing:     Rarely

This event is mainly used for Windows Filtering Platform troubleshooting and typically has little to no security relevance.


Volume:     High

On a Windows Server, this event can produce 40–50 occurrences every 2–3 minutes as Windows Firewall dynamically adds and deletes non-persistent ALE layer filters in response to services binding and releasing ports. Unlike the other WFP events which are bounded to boot, 5447 is a continuous stream on any active system.


Microsoft Documentation

Event ID - 5447



NameFieldInsertion StringOSExample
Process IDProcessId%1Any 284
Security IDUserSid%2Any S-1-5-19
Account NameUserName%3Any NT AUTHORITY\LOCAL SERVICE
Provider IDProviderKey%4Any {DECC16CA-3F33-...}
Provider NameProviderName%5Any Microsoft Corporation
Change TypeChangeType%6Any %%16385
Filter IDFilterKey%7Any {91334E6D-FFAB-...}
Filter NameFilterName%8Any Port Scanning Prevention Filter
Filter TypeFilterType%9Any %%16388
Filter Run-Time IDFilterId%10Any 100100
Layer IDLayerKey%11Any {AC4A9833-F69D-...}
Layer NameLayerName%12Any Inbound Transport v4 Layer
Layer Run-Time IDLayerId%13Any 13
WeightWeight%14Any 13835058055315718144
ConditionsConditions%15Any (multi-line)
Filter ActionAction%16Any %%16391
Callout IDCalloutKey%17Any {EDA08606-2494-...}
Callout NameCalloutName%18Any WFP Built-in Silent Drop Transport


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Other Policy Change Events"



LEFT/RIGHT arrow keys for navigation

Back to List