Event ID 4947 — Firewall Rule Processing
Applies To: Windows Server 2008
Windows Firewall with Advanced Security receives its rules from local security policy stored in the system registry, and from Group Policy delivered by Active Directory. After receiving a new or modified policy, Windows Firewall must process each rule in the applied policies to interpret what network traffic is to be blocked, allowed, or protected by using Internet Protocol security (IPsec).
When appropriate auditing events are enabled (https://go.microsoft.com/fwlink/?linkid=92666), Windows reports successes and failures, both in retrieving policy and in processing the rules defined in the policy.
Event Details
Product: | Windows Operating System |
ID: | 4947 |
Source: | Microsoft-Windows-Security-Auditing |
Version: | 6.0 |
Symbolic Name: | SE_AUDITID_ETW_FIREWALL_RULE_CHANGE |
Message: | A change has been made to Windows Firewall exception list. A rule was modified. %t Profile Changed:%t%1 Modified Rule: %tRule ID:%t%2 %tRule Name:%t%3 |
Resolve
This is a normal condition. No further action is required.