Event ID 854 – The Windows Firewall logging settings have changed.
When the logging settings of Windows Firewall are changed, event ID 854 is logged by Windows. Such a change is usually instituted by an administrator or a group policy refresh.
This log data provides the following information:
- Policy Origin
- Profile Changed
- New Settings - Log Dropped Packets
- New Settings - Log Successful Connections
- Old Settings - Log Dropped Packets
- Old Settings - Log Successful Connections
Why does event ID 854 need to be monitored?
- To check if the settings defined for the Windows Firewall are in line with the established standard settings
- To monitor all changes made locally to Windows Firewall settings
ADAudit Plus helps you avoid the GPOs monitoring complexities with real-time pre-configured reports and auditing of the changes along with alerts within a Domain & OU. The advanced Group Policy settings real-time audit reports highlight the elusive change details, and also provide the old and new values of the modified attributes.
Event 854 applies to the following operating systems:
- Windows 2003 and XP
Corresponding event ID in Windows 2008 and Windows Vista is 4950.