Microsoft-Windows-SEC-WFP
4 events across 1 channel
Event ID 1 —
Fields
| Name | Description |
|---|---|
ModuleTag | — |
ProcessId | — |
ProcessStartKey | — |
ProcessCreationTime | — |
IsBlocked | — |
Direction | — |
IsExistingConnection | — |
FilterId | — |
LayerId | — |
InterfaceIndex | — |
Protocol | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
Event ID 2 —
Fields
| Name | Description |
|---|---|
ModuleTag | — |
ProcessId | — |
ProcessStartKey | — |
ProcessCreationTime | — |
IsBlocked | — |
Direction | — |
IsExistingConnection | — |
FilterId | — |
LayerId | — |
InterfaceIndex | — |
Protocol | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
Event ID 3 —
Fields
| Name | Description |
|---|---|
ModuleTag | — |
ProcessId | — |
ProcessStartKey | — |
ProcessCreationTime | — |
IsBlocked | — |
Direction | — |
IsExistingConnection | — |
FilterId | — |
LayerId | — |
InterfaceIndex | — |
Protocol | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
Event ID 4 —
Fields
| Name | Description |
|---|---|
ModuleTag | — |
RuleId | — |
LayerId | — |
Action | — |
FieldId | — |
MatchType | — |
DataType | — |
IsBlocked | — |