Firewall Rule Change

Firewall Rule Change

Configuration

query

EventID:2005

config

Key | Value — | — type | aggregation-v1 query | EventID:2005 streams | [5f74fe0891d2ba1b645adb8d] conditions | {expression:null} search_within_ms | 3600000 execute_every_ms | 3600000

Windows Windows Firewall

If client workstations are taking advantage of the built-in host-based Windows Firewall, then there is value in collecting events to track the firewall status.


Last modified December 31, 1969