EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Policy Change (8)
Operating Systems
  • Windows 10 (8)
  • Windows 11 (8)
  • Windows 2008 (8)
  • Windows 2008 R2 (8)
  • Windows 2012 (8)
  • Windows 2012 R2 (8)
  • Windows 2016 (8)
  • Windows 2019 (8)
  • Windows 2022 (8)
  • Windows 7 (8)
  • Windows 8 (8)
  • Windows 8.1 (8)
  • Windows Vista (8)
Tags
  • Audit Failure (4)
  • Audit Success (4)
Auditing
  • Always (8)
Volume
  • Low (8)
Audit Subcategory
  • MPSSVC Rule-Level Policy Change (8)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4945 A rule was listed when the Windows Firewall started
Audit Success
4946 A change was made to the Windows Firewall exception list. A rule was added
Audit Success
4947 A change was made to the Windows Firewall exception list. A rule was modified
Audit Success
4948 A change was made to the Windows Firewall exception list. A rule was deleted
Audit Success
4951 Windows Firewall ignored a rule because its major version number is not recognized
Audit Failure
4952 Windows Firewall ignored parts of a rule because its minor version number is not recognized
Audit Failure
4953 Windows Firewall ignored a rule because it could not be parsed
Audit Failure
4957 Windows Firewall did not apply the following rule
Audit Failure



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy