Object Access Event: 5154

Active Directory Auditing Tool

The Who, Where and When information is very important for an administrator to have complete knowledge of all activities that occur on their Active Directory. This helps them identify any desired / undesired activity happening. ADAudit Plus assists an administrator with this information in the form of reports. In real-time, ensure critical resources in the network like the Domain Controllers are audited, monitored and reported with the entire information on AD objects - Users, Groups, GPO, Computer, OU, DNS, AD Schema and Configuration changes with 200+ detailed event specific GUI reports and email alerts.

Object Access » Object Access Event: 5154

Event ID 5154 – The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.

Event ID 5154
Category Object Access: Audit Platform Connection
Type Success Audit

When Windows Filtering Platform allows an application or service to listen on a TCP or UDP port for incoming connections, event ID 5154 is logged. This event also logs the filter, port, or program which allowed the incoming connection.

This event log contains the following information:

  • Process ID
  • Application Name
  • Source Address
  • Source Type
  • Protocol
  • Filter Run-Time ID
  • Layer Name
  • Layer Run-Time

Why does event ID 5154 need to be monitored?

  • To ensure only whitelisted applications are allowed to listen on specific ports
  • To monitor specific port numbers, and activities regarding them
  • To ensure applications listen in on only specific IP addresses
  • To check the protocol that is being used by certain applications
  • To monitor restricted applications
  • To monitor for informational purposes

Event 5154 applies to the following operating systems:

  • Windows 2008 R2 and 7
  • Windows 2012 R2 and 8.1
  • Windows 2016 and 10