Event logs filling up with event IDs 5157, 5152, 5156


what needs adjusted event ids 5157, 5152 , 5156 do not continue flood logs? 

hi,

what needs adjusted event ids 5157, 5152 , 5156 do not continue flood logs? 

to prevent these event ids above being logged, on machine logged, please run these commands below administrator:

auditpol /set /subcategory:"filtering platform packet drop" /success: disable /failure: disable

auditpol /set /subcategory:"filtering platform connection" /success: disable /failure: disable

more information you:

audit filtering platform connection

https://technet.microsoft.com/en-us/library/dd772749(v=ws.10).aspx

the windows filtering platform has blocked bind local port

http://blogs.technet.com/b/instan/archive/2009/01/08/the-windows-filtering-platform-has-blocked-a-bind-to-a-local-port.aspx

best regards,

amy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL