Event ID 5031 – The Windows Firewall Service Blocked An Application From Accepting Incoming Connections On The Network
|Category||Object Access: Filtering Platform Connection|
When the Windows Filtering Platform blocks an application from accepting any incoming connections on the network, event ID 5031 is logged. This is the default setting, unless firewall rules have been set up for specific applications in Windows Firewall.
This event log contains the following information:
Why does event ID 5031 need to be monitored?
- To detect those applications which do not have Windows Firewall rules
- To monitor the activities of a particular application (trackable via "Application Name")
- To check if certain applications are restricted
Event 5031 applies to the following operating systems:
- Windows 2008 R2 and 7
- Windows 2012 R2 and 8.1
- Windows 2016 and 10
Explore Active Directory auditing and reporting with ADAudit Plus.
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools