Windows Security Log Events
All Sources
Windows Audit
SharePoint Audit
(
LOGbinder for SharePoint
)
SQL Server Audit
(
LOGbinder for SQL Server
)
Exchange Audit
(
LOGbinder for Exchange
)
Sysmon
(
MS Sysinternals Sysmon
)
Windows Audit Categories:
All categories
Account Logon
Account Management
Directory Service
Logon/Logoff
Non Audit (Event Log)
Object Access
Policy Change
Privilege Use
Process Tracking
System
Uncategorized
Subcategories:
All subcategories
Audit Policy Change
Authentication Policy Change
Authorization Policy Change
Filtering Platform Policy Change
MPSSVC Rule-Level Policy Change
Other Policy Change Events
Windows Versions:
All events
Win2000, XP and Win2003 only
Win2008, Win2012R2, Win2016 and Win10+, Win2019
Required when sub-category selected.
Category:
Policy Change
Subcategory:
MPSSVC Rule-Level Policy Change
Windows
4944
The following policy was active when the Windows Firewall started
Windows
4945
A rule was listed when the Windows Firewall started
Windows
4946
A change has been made to Windows Firewall exception list. A rule was added
Windows
4947
A change has been made to Windows Firewall exception list. A rule was modified
Windows
4948
A change has been made to Windows Firewall exception list. A rule was deleted
Windows
4949
Windows Firewall settings were restored to the default values
Windows
4950
A Windows Firewall setting has changed
Windows
4951
A rule has been ignored because its major version number was not recognized by Windows Firewall
Windows
4952
Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall
Windows
4954
Windows Firewall Group Policy settings has changed. The new settings have been applied
Windows
4956
Windows Firewall has changed the active profile
Windows
4957
Windows Firewall did not apply the following rule
Windows
4958
Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer
Stay up-to-date on the Latest in Cybersecurity
Sign up for the Ultimate IT Security newsletter to hear about the latest webinars, patches, CVEs, attacks, and more.
Work Email:
Upcoming Webinars
Additional Resources
Encyclopedia
•
Event IDs
•
All Event IDs
•
Audit Policy
Go To Event ID:
Security Log
Quick Reference
Chart
Download now!
Tweet
User name:
Password:
/
Forgot?
Register
October 2025
Patch Tuesday
"Patch Tuesday - 172 Updates Today and 6 Zero-Days! " - sponsored by LOGbinder
Home
Cookies help us deliver the best experience on our website. By using our website, you agree to the use of cookies.