Microsoft-Windows-Base-Filtering-Engine-Resource-Flows

4 events across 1 channel

Event IDTitleChannel
2002New Resource FlowOperational
2003Resource Flow ClosedOperational
2004New Resource FlowOperational
2005Resource Flow ClosedOperational

Event ID 2002 — New Resource Flow

Provider
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Channel
Operational
Opcode
Info

Description

New Resource Flow.

Message #

New Resource Flow

Fields #

NameDescription
ConnectionUsedId UInt64
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
RemoteIPAddress Binary
LocalIPAddress Binary
RemotePort UInt16
LocalPort UInt16
StartTime FILETIME

Event ID 2003 — Resource Flow Closed

Provider
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Channel
Operational
Opcode
Info

Description

Resource Flow Closed.

Message #

Resource Flow Closed

Fields #

NameDescription
ConnectionUsedId UInt64
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
RemoteIPAddress Binary
LocalIPAddress Binary
RemotePort UInt16
LocalPort UInt16
StartTime FILETIME
CloseTime FILETIME

Event ID 2004 — New Resource Flow

Provider
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Channel
Operational
Opcode
Info

Description

New Resource Flow.

Message #

New Resource Flow

Fields #

NameDescription
ConnectionUsedId UInt64
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
RemoteIPAddress UInt32
LocalIPAddress UInt32
RemotePort UInt16
LocalPort UInt16
StartTime FILETIME

Event ID 2005 — Resource Flow Closed

Provider
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Channel
Operational
Opcode
Info

Description

Resource Flow Closed.

Message #

Resource Flow Closed

Fields #

NameDescription
ConnectionUsedId UInt64
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
RemoteIPAddress UInt32
LocalIPAddress UInt32
RemotePort UInt16
LocalPort UInt16
StartTime FILETIME
CloseTime FILETIME