Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
4 events across 1 channel
| Event ID | Title | Channel |
|---|---|---|
| 2002 | New Resource Flow | Operational |
| 2003 | Resource Flow Closed | Operational |
| 2004 | New Resource Flow | Operational |
| 2005 | Resource Flow Closed | Operational |
Event ID 2002 — New Resource Flow
Description
New Resource Flow.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | — |
Protocol UInt8 | — Known values
|
RemoteIPAddress Binary | — |
LocalIPAddress Binary | — |
RemotePort UInt16 | — |
LocalPort UInt16 | — |
StartTime FILETIME | — |
Event ID 2003 — Resource Flow Closed
Description
Resource Flow Closed.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | — |
Protocol UInt8 | — Known values
|
RemoteIPAddress Binary | — |
LocalIPAddress Binary | — |
RemotePort UInt16 | — |
LocalPort UInt16 | — |
StartTime FILETIME | — |
CloseTime FILETIME | — |
Event ID 2004 — New Resource Flow
Description
New Resource Flow.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | — |
Protocol UInt8 | — Known values
|
RemoteIPAddress UInt32 | — |
LocalIPAddress UInt32 | — |
RemotePort UInt16 | — |
LocalPort UInt16 | — |
StartTime FILETIME | — |
Event ID 2005 — Resource Flow Closed
Description
Resource Flow Closed.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | — |
Protocol UInt8 | — Known values
|
RemoteIPAddress UInt32 | — |
LocalIPAddress UInt32 | — |
RemotePort UInt16 | — |
LocalPort UInt16 | — |
StartTime FILETIME | — |
CloseTime FILETIME | — |