Windows Security Log Events
All Sources
Windows Audit
SharePoint Audit
(
LOGbinder for SharePoint
)
SQL Server Audit
(
LOGbinder for SQL Server
)
Exchange Audit
(
LOGbinder for Exchange
)
Sysmon
(
MS Sysinternals Sysmon
)
Windows Audit Categories:
All categories
Account Logon
Account Management
Directory Service
Logon/Logoff
Non Audit (Event Log)
Object Access
Policy Change
Privilege Use
Process Tracking
System
Uncategorized
Subcategories:
All subcategories
Audit Policy Change
Authentication Policy Change
Authorization Policy Change
Filtering Platform Policy Change
MPSSVC Rule-Level Policy Change
Other Policy Change Events
Windows Versions:
All events
Win2000, XP and Win2003 only
Win2008, Win2012R2, Win2016 and Win10+, Win2019
Required when sub-category selected.
Category:
Policy Change
Subcategory:
Filtering Platform Policy Change
Windows
4709
IPsec Services was started
Windows
4710
IPsec Services was disabled
Windows
4711
PAStore Engine (1%)
Windows
4712
IPsec Services encountered a potentially serious failure
Windows
5440
The following callout was present when the Windows Filtering Platform Base Filtering Engine started
Windows
5441
The following filter was present when the Windows Filtering Platform Base Filtering Engine started
Windows
5442
The following provider was present when the Windows Filtering Platform Base Filtering Engine started
Windows
5443
The following provider context was present when the Windows Filtering Platform Base Filtering Engine started
Windows
5444
The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started
Windows
5446
A Windows Filtering Platform callout has been changed
Windows
5448
A Windows Filtering Platform provider has been changed
Windows
5449
A Windows Filtering Platform provider context has been changed
Windows
5450
A Windows Filtering Platform sub-layer has been changed
Windows
5456
PAStore Engine applied Active Directory storage IPsec policy on the computer
Windows
5457
PAStore Engine failed to apply Active Directory storage IPsec policy on the computer
Windows
5458
PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer
Windows
5459
PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer
Windows
5460
PAStore Engine applied local registry storage IPsec policy on the computer
Windows
5461
PAStore Engine failed to apply local registry storage IPsec policy on the computer
Windows
5462
PAStore Engine failed to apply some rules of the active IPsec policy on the computer
Windows
5463
PAStore Engine polled for changes to the active IPsec policy and detected no changes
Windows
5464
PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services
Windows
5465
PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully
Windows
5466
PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead
Windows
5467
PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy
Windows
5468
PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes
Windows
5471
PAStore Engine loaded local storage IPsec policy on the computer
Windows
5472
PAStore Engine failed to load local storage IPsec policy on the computer
Windows
5473
PAStore Engine loaded directory storage IPsec policy on the computer
Windows
5474
PAStore Engine failed to load directory storage IPsec policy on the computer
Windows
5477
PAStore Engine failed to add quick mode filter
Stay up-to-date on the Latest in Cybersecurity
Sign up for the Ultimate IT Security newsletter to hear about the latest webinars, patches, CVEs, attacks, and more.
Work Email:
Upcoming Webinars
Identity-First Security for AI Agents: Defending a New Attack Surface Across Cloud and SaaS
Additional Resources
Encyclopedia
•
Event IDs
•
All Event IDs
•
Audit Policy
Go To Event ID:
Security Log
Quick Reference
Chart
Download now!
Tweet
User name:
Password:
/
Forgot?
Register
April 2026
Patch Tuesday
"Patch Tuesday- Only 2 Zero-Days but a Massive Month of Updates " - sponsored by LOGbinder
Home
Cookies help us deliver the best experience on our website. By using our website, you agree to the use of cookies.