Windows Security Log Events



(LOGbinder for SharePoint)
(LOGbinder for SQL Server)
(LOGbinder for Exchange)
(MS Sysinternals Sysmon)
Windows Audit Categories:

Subcategories:

Windows Versions:
Required when sub-category selected.

Windows 4944 The following policy was active when the Windows Firewall started
Windows 4945 A rule was listed when the Windows Firewall started
Windows 4946 A change has been made to Windows Firewall exception list. A rule was added
Windows 4947 A change has been made to Windows Firewall exception list. A rule was modified
Windows 4948 A change has been made to Windows Firewall exception list. A rule was deleted
Windows 4949 Windows Firewall settings were restored to the default values
Windows 4950 A Windows Firewall setting has changed
Windows 4951 A rule has been ignored because its major version number was not recognized by Windows Firewall
Windows 4952 Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall
Windows 4954 Windows Firewall Group Policy settings has changed. The new settings have been applied
Windows 4956 Windows Firewall has changed the active profile
Windows 4957 Windows Firewall did not apply the following rule
Windows 4958 Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer

 

Additional Resources
    Encyclopedia
    Event IDs
    All Event IDs
    Audit Policy

    Go To Event ID:

    Security Log
    Quick Reference
    Chart
    Download now!