Firewall Rule Add

Firewall Rule Add

Configuration

query

EventID:2004

config

Key | Value — | — type | aggregation-v1 query | EventID:2004 streams | [5f74fe0891d2ba1b645adb8d] conditions | {expression:null} search_within_ms | 3600000 execute_every_ms | 3600000

Windows Windows Firewall

If client workstations are taking advantage of the built-in host-based Windows Firewall, then there is value in collecting events to track the firewall status.


Last modified December 31, 1969