Event ID 5447
A Windows Filtering Platform filter has been changed.A Windows Filtering Platform filter has been changed.
Subject:
Security ID: %2
Account Name: %3
Process Information:
Process ID: %1
Provider Information:
ID: %4
Name: %5
Change Information:
Change Type: %6
Filter Information:
ID: %7
Name: %8
Type: %9
Run-Time ID: %10
Layer Information:
ID: %11
Name: %12
Run-Time ID: %13
Callout Information:
ID: %17
Name: %18
Additional Information:
Weight: %14
Conditions: %15
Filter Action: %16This event generates every time a Windows Filtering Platform filter has been changed. It typically generates during Group Policy update procedures.
Auditing:
Rarely
This event is mainly used for Windows Filtering Platform troubleshooting and typically has little to no security relevance.
Volume:
High
On a Windows Server, this event can produce 40–50 occurrences every 2–3 minutes as Windows Firewall dynamically adds and deletes non-persistent ALE layer filters in response to services binding and releasing ports. Unlike the other WFP events which are bounded to boot, 5447 is a continuous stream on any active system.
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Other Policy Change Events"
LEFT/RIGHT arrow keys for navigation
Back to List