System32
Sysmon
Events
Compliance
Validator
TLS/SSL
GeoIP
Tools
Windows Security Events
Audit Category
Object Access
(5)
Logon/Logoff
(3)
Operating Systems
Windows 10
(8)
Windows 2008
(8)
Windows 2008 R2
(8)
Windows 2012
(8)
Windows 2012 R2
(8)
Windows 2016
(8)
Windows 2019
(8)
Windows 2022
(8)
Windows 7
(8)
Windows 8
(8)
Windows 8.1
(8)
Windows Vista
(8)
Windows 11
(7)
Windows 2025
(2)
Tags
Audit Failure
(3)
Audit Success
(3)
Auditing
Rarely
(6)
Volume
High
(6)
Very high
(3)
Medium
(1)
Audit Subcategory
Filtering Platform Connection
(4)
IPsec Quick Mode
(3)
Filtering Platform Packet Drop
(1)
AppLocker
All AppLocker events
EventSentry
All EventSentry events
Security
All Windows Security events
Sysmon
All Sysmon events
ID
Event Description
4654
An IPsec quick mode negotiation failed
Audit Failure
5152
The Windows Filtering Platform has blocked a packet.
Audit Failure
5154
The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Audit Success
5156
The Windows Filtering Platform has allowed a connection.
Audit Success
5157
The Windows Filtering Platform has blocked a connection.
Audit Failure
5158
The Windows Filtering Platform has permitted a bind to a local port.
Audit Success
5451
An IPsec quick mode security association was established.
5452
An IPsec quick mode security association ended.