Windows Security Log Event ID 854
Operating Systems Windows XP
Windows Server 2003
CategoryPolicy Change
Type Success
Corresponding events
in Windows 2008
and Vista
4950  
Discussions on Event ID 854
Ask a question about this event

854: The Windows Firewall logging settings have changed

On this page

Windows logs this event when an administrator changes the local policy of the Windows Firewall or a group policy refresh results in a change to the Windows Firewall logging settings.

  • Policy origin: Group Policy or Local Policy
  • Profile changed: Standard or Domain

New Settings:

  • Log dropped packets: Enabled or Disabled
  • Log successful connections: Enabled or Disabled

Old Settings:

  • Log dropped packets: Enabled or Disabled
  • Log successful connections: Enabled or Disabled

 

Top 10 Windows Security Events to Monitor

The Windows Firewall logging settings have changed.
 
Policy origin: Local Policy
Profile changed: -
New Settings:
     Log dropped packets: Enabled
     Log successful connections: Enabled
Old Settings:
     Log dropped packets: Disabled
     Log successful connections: Disabled

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this



Training for the Windows Security Log