EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Object Access (5)
  • Logon/Logoff (3)
Operating Systems
  • Windows 10 (8)
  • Windows 2008 (8)
  • Windows 2008 R2 (8)
  • Windows 2012 (8)
  • Windows 2012 R2 (8)
  • Windows 2016 (8)
  • Windows 2019 (8)
  • Windows 2022 (8)
  • Windows 7 (8)
  • Windows 8 (8)
  • Windows 8.1 (8)
  • Windows Vista (8)
  • Windows 11 (7)
  • Windows 2025 (2)
Tags
  • Audit Failure (3)
  • Audit Success (3)
Auditing
  • Rarely (6)
Volume
  • High (6)
  • Very high (3)
  • Medium (1)
Audit Subcategory
  • Filtering Platform Connection (4)
  • IPsec Quick Mode (3)
  • Filtering Platform Packet Drop (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4654 An IPsec quick mode negotiation failed
Audit Failure
5152 The Windows Filtering Platform has blocked a packet.
Audit Failure
5154 The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Audit Success
5156 The Windows Filtering Platform has allowed a connection.
Audit Success
5157 The Windows Filtering Platform has blocked a connection.
Audit Failure
5158 The Windows Filtering Platform has permitted a bind to a local port.
Audit Success
5451 An IPsec quick mode security association was established.
5452 An IPsec quick mode security association ended.



© netikus.net ltd 2002-2026 | EventSentry Events | Codes | Sysmon | STIG | AppLocker | Privacy Policy