Event ID 848
The following policy was active when the Windows Firewall startedThe following policy was active when the Windows Firewall started.
Group Policy applied: %1
Profile used: %2
Operational mode: %3
Allow remote administration: %4
Allow unicast responses to multicast/broadcast traffic: %5
Security Logging:
Log dropped packets: %6
Log successful connections %7Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /category:"Policy Change"
LEFT/RIGHT arrow keys for navigation
Back to List