EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Logon/Logoff (13)
  • Policy Change (1)
Operating Systems
  • Windows 10 (14)
  • Windows 11 (14)
  • Windows 2008 (14)
  • Windows 2008 R2 (14)
  • Windows 2012 (14)
  • Windows 2012 R2 (14)
  • Windows 2016 (14)
  • Windows 2019 (14)
  • Windows 2022 (14)
  • Windows 2025 (14)
  • Windows 7 (14)
  • Windows 8 (14)
  • Windows 8.1 (14)
  • Windows Vista (14)
Tags
  • Audit Failure (3)
  • Audit Success (2)
Auditing
  • Rarely (3)
Volume
  • High (2)
  • Low (1)
Audit Subcategory
  • IPsec Extended Mode (6)
  • IPsec Main Mode (4)
  • IPsec Quick Mode (3)
  • Filtering Platform Policy Change (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
IDEvent Description
4650 An IPsec main mode security association was established
Audit Success
4651 An IPsec main mode security association was established
Audit Success
4652 An IPsec main mode negotiation failed
Audit Failure
4653 An IPsec main mode negotiation failed
Audit Failure
4654 An IPsec quick mode negotiation failed
Audit Failure
4979 IPsec main mode and extended mode security associations were established
4980 IPsec main mode and extended mode security associations were established
4981 IPsec main mode and extended mode security associations were established
4982 IPsec main mode and extended mode security associations were established
4983 An IPsec extended mode negotiation failed
4984 An IPsec extended mode negotiation failed
5443 The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.
5451 An IPsec quick mode security association was established.
5452 An IPsec quick mode security association ended.



© netikus.net ltd 2002-2026 | EventSentry Events | Codes | Sysmon | STIG | AppLocker | Privacy Policy