Microsoft-Windows-SEC-WFP

4 events across 1 channel

Event IDTitleChannel
1Operational
2Operational
3Operational
4Operational

Event ID 1 —

Provider
Microsoft-Windows-SEC-WFP
Channel
Operational

Fields

NameDescription
ModuleTag
ProcessId
ProcessStartKey
ProcessCreationTime
IsBlocked
Direction
IsExistingConnection
FilterId
LayerId
InterfaceIndex
Protocol
LocalAddressLength
LocalAddress
RemoteAddressLength
RemoteAddress

Event ID 2 —

Provider
Microsoft-Windows-SEC-WFP
Channel
Operational

Fields

NameDescription
ModuleTag
ProcessId
ProcessStartKey
ProcessCreationTime
IsBlocked
Direction
IsExistingConnection
FilterId
LayerId
InterfaceIndex
Protocol
LocalAddressLength
LocalAddress
RemoteAddressLength
RemoteAddress

Event ID 3 —

Provider
Microsoft-Windows-SEC-WFP
Channel
Operational

Fields

NameDescription
ModuleTag
ProcessId
ProcessStartKey
ProcessCreationTime
IsBlocked
Direction
IsExistingConnection
FilterId
LayerId
InterfaceIndex
Protocol
LocalAddressLength
LocalAddress
RemoteAddressLength
RemoteAddress

Event ID 4 —

Provider
Microsoft-Windows-SEC-WFP
Channel
Operational

Fields

NameDescription
ModuleTag
RuleId
LayerId
Action
FieldId
MatchType
DataType
IsBlocked