Windows Security Log Event ID 4947

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Category
 • Subcategory
Policy Change
 • MPSSVC Rule-Level Policy Change
Type Success
Corresponding events
in Windows 2003
and before
851 , 852  
Discussions on Event ID 4947
Ask a question about this event

4947: A change has been made to Windows Firewall exception list. A rule was modified

On this page

Exceptions define traffic that bypasses other Windows Firewall rules.

Profile Changed: Domain, Private, Public, All

Free Security Log Resources by Randy

Description Fields in 4947

Modified Rule:

Name and ID of the rule modified.
These rules are defined in Group Policy and in the Windows Firewall with Advanced Services MMC console

Supercharger Free Edition


Centrally manage WEC subscriptions.

Free.

 

Examples of 4947

A change has been made to Windows Firewall exception list. A rule was modified.

Profile Changed: -

Modified Rule:

   Rule ID: WMI-RPCSS-In-TCP
   Rule Name: @FirewallAPI.dll,-34252

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Additional Resources