5156 Show App IP Connections

OverView

When you open the Security Event log, the log may contain many “Filtering Platform Connection” events. The event ID of these entries maybe 5156 or 5158. The security log may record close to 100 events per minute, containing the event ID 5156 or 5158. This causes the security event log to become full very quickly.

  • Not enabled on default

  • Shows program that made connection and associated IP

  • Fills up logs quickly, and can be enabled by other programs.

Sample Event ID 5156 entry

Sample Event ID 5158 entry

Auditpol

Last updated