Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
4 events across 1 channel
| Event | Title | Channel |
|---|---|---|
| 2002 | New Resource Flow | Operational |
| 2003 | Resource Flow Closed | Operational |
| 2004 | New Resource Flow | Operational |
| 2005 | Resource Flow Closed | Operational |
Event ID 2002: New Resource Flow
#Description
New Resource Flow.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | |
Protocol UInt8 | Known values
|
RemoteIPAddress Binary | |
LocalIPAddress Binary | |
RemotePort UInt16 | |
LocalPort UInt16 | |
StartTime FILETIME |
Event ID 2003: Resource Flow Closed
#Description
Resource Flow Closed.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | |
Protocol UInt8 | Known values
|
RemoteIPAddress Binary | |
LocalIPAddress Binary | |
RemotePort UInt16 | |
LocalPort UInt16 | |
StartTime FILETIME | |
CloseTime FILETIME |
Event ID 2004: New Resource Flow
#Description
New Resource Flow.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | |
Protocol UInt8 | Known values
|
RemoteIPAddress UInt32 | |
LocalIPAddress UInt32 | |
RemotePort UInt16 | |
LocalPort UInt16 | |
StartTime FILETIME |
Event ID 2005: Resource Flow Closed
#Description
Resource Flow Closed.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | |
Protocol UInt8 | Known values
|
RemoteIPAddress UInt32 | |
LocalIPAddress UInt32 | |
RemotePort UInt16 | |
LocalPort UInt16 | |
StartTime FILETIME | |
CloseTime FILETIME |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 92765247-03a9-4ae3-a575-b42264616e78
Defined in fwpkclnt.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.4647 · captured 2026-06-02
- Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.6584 · captured 2026-06-02
Downloads
- Microsoft-Windows-Base-Filtering-Engine-Resource-Flows registered manifest XML (WS2022-20348.4893) manifest-xml
- Microsoft-Windows-Base-Filtering-Engine-Resource-Flows registered manifest XML (Win11-26200.6584) manifest-xml