Microsoft-Windows-Base-Filtering-Engine-Connections
2 events across 1 channel
| Event ID | Title | Channel |
|---|---|---|
| 2000 | New Connection | Operational |
| 2001 | Connection Closed | Operational |
Event ID 2000 — New Connection
Description
New Connection.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionId UInt64 | — |
MachineAuthenticationMethod UInt32 | — |
RemoteMachineAccount UnicodeString | — |
UserAuthenticationMethod UInt32 | — |
RemoteUserAcount UnicodeString | — |
RemoteIPAddress UnicodeString | — |
LocalIPAddress UnicodeString | — |
TechnologyProviderKey GUID | — |
IPsecTrafficMode UInt32 | — |
DHGroup UInt32 | — |
StartTime SYSTEMTIME | — |
Event ID 2001 — Connection Closed
Description
Connection Closed.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionId UInt64 | — |
MachineAuthenticationMethod UInt32 | — |
RemoteMachineAccount UnicodeString | — |
UserAuthenticationMethod UInt32 | — |
RemoteUserAcount UnicodeString | — |
RemoteIPAddress UnicodeString | — |
LocalIPAddress UnicodeString | — |
TechnologyProviderKey GUID | — |
IPsecTrafficMode UInt32 | — |
BytesTransferredInbound UInt64 | — |
BytesTransferredOutbound UInt64 | — |
BytesTransferredTotal UInt64 | — |
StartTime SYSTEMTIME | — |
CloseTime SYSTEMTIME | — |