Microsoft-Windows-Base-Filtering-Engine-Connections

2 events across 1 channel

Event IDTitleChannel
2000New ConnectionOperational
2001Connection ClosedOperational

Event ID 2000 — New Connection

Provider
Microsoft-Windows-Base-Filtering-Engine-Connections
Channel
Operational

Message

New Connection

Fields

NameDescription
ConnectionId
MachineAuthenticationMethod
RemoteMachineAccount
UserAuthenticationMethod
RemoteUserAcount
RemoteIPAddress
LocalIPAddress
TechnologyProviderKey
IPsecTrafficMode
DHGroup
StartTime

Event ID 2001 — Connection Closed

Provider
Microsoft-Windows-Base-Filtering-Engine-Connections
Channel
Operational

Message

Connection Closed

Fields

NameDescription
ConnectionId
MachineAuthenticationMethod
RemoteMachineAccount
UserAuthenticationMethod
RemoteUserAcount
RemoteIPAddress
LocalIPAddress
TechnologyProviderKey
IPsecTrafficMode
BytesTransferredInbound
BytesTransferredOutbound
BytesTransferredTotal
StartTime
CloseTime