EVID 4956, 4957 : Firewall Action (Deutsch - Security)
Event Details
Event Type | Audit MPSSVC Rule-Level Policy Change |
---|---|
Event Description | |
Event IDs | 4956, 4957 |
Log Fields and Parsing
This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.
Log Field | LogRhythm Default | LogRhythm Default v2.0 | |
---|---|---|---|
Provider | N/A | N/A | |
EventID | <vmid> | <vmid> | |
Version | N/A | N/A | |
Level | <severity> | <severity> | |
Task | <vendorinfo> | <vendorinfo> | |
Opcode | N/A | N/A | |
Keywords | N/A | <result>, <tag1> | |
TimeCreated | N/A | N/A | |
EventRecordID | N/A | N/A | |
Correlation | N/A | N/A | |
Execution | N/A | N/A | |
Processid | N/A | N/A | |
Channel | N/A | N/A | |
Computer | <dname> | <dname> | |
Profile Used / Change | N/A | <policy> | |
Reason For Rejection | N/A | <reason> | |
RuleID | N/A | <object> | |
RuleName | N/A | <objectname> | |
RuleAttr | N/A | <reason> | |
TargetUserName | N/A | N/A | |
DomainPolicyChanged | N/A | N/A | |
SubjectUserID | N/A | N/A | |
SubjectUserName | N/A | N/A | |
SubjectDomainName | N/A | N/A | |
SubjectLogonId | N/A | N/A | |
TargetUserName | N/A | N/A | |
TargetUserDomain | N/A | N/A | |
NewProcessname | N/A | N/A | |
ServiceName | N/A | N/A | |
Security ID | N/A | N/A | |
Logon ID | N/A | N/A | |
Object Type | N/A | N/A | |
Object Name | N/A | N/A | |
File Name | N/A | N/A | |
Process ID | N/A | N/A | |
Group Name | N/A | N/A | |
Task Name | N/A | N/A | |
New Active Profile | <account> | N/A | |
Control information | <object> | N/A | |
Object Name | <objectname> | N/A | |
Root cause | <tag1> | N/A |
Log Processing Settings
This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.
LogRhythm Default
Regex ID | Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|---|
1004689 | EVID 4956 & 4957 : Firewall Action | Base Rule | General Firewall Event | Information |
EVID 4956 : Firewall Changed Active Profile | Sub Rule | Configuration Modified : Security | Configuration | |
EVID 4957 : Firewall Rule Not Applied | Sub Rule | Firewall Rule Not Applied | Warning |
LogRhythm Default v2.0
Regex ID | Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|---|
1011124 | V 2.0 : Windows Filtering Platform Rule Events | Base Rule | Configuration Modified : Security | Configuration |
V 2.0 : EVID 4945 : WFP Rule Listed On Firewll Str | Sub Rule | Rule Listed On Firewall Start | Information | |
V 2.0 : EVID 4946 : WFP - Rule Added | Sub Rule | Configuration Loaded : Security | Configuration | |
V 2.0 : EVID 4947 : WFP - Rule Modfied | Sub Rule | Configuration Modified : Security | Configuration | |
V 2.0 : EVID 4948 : WFP - Rule Deleted | Sub Rule | Configuration Deleted : Security | Configuration | |
V 2.0 : EVID 4951 : WFP - Rule Ignored | Sub Rule | Firewall Rule Not Applied | Warning | |
V 2.0 : EVID 4952 : WFP - Rule Ignored | Sub Rule | Firewall Rule Not Applied | Warning | |
V 2.0 : EVID 4953 : WFP - Rule Ignored | Sub Rule | Firewall Rule Not Applied | Warning | |
V 2.0 : EVID 4956 : WFP - Active Profile Changed | Sub Rule | Configuration Modified : Security | Configuration | |
V 2.0 : EVID 4957 : WFP - Rule Ignored | Sub Rule | Firewall Rule Not Applied | Warning | |
V 2.0 : EVID 4958 : WFP - Rule Ignored | Sub Rule | Firewall Rule Not Applied | Warning |