Event logs filling up with event IDs 5157, 5152, 5156


what needs adjusted event ids 5157, 5152 , 5156 do not continue flood logs? 

hi,

what needs adjusted event ids 5157, 5152 , 5156 do not continue flood logs? 

to prevent these event ids above being logged, on machine logged, please run these commands below administrator:

auditpol /set /subcategory:"filtering platform packet drop" /success: disable /failure: disable

auditpol /set /subcategory:"filtering platform connection" /success: disable /failure: disable

more information you:

audit filtering platform connection

https://technet.microsoft.com/en-us/library/dd772749(v=ws.10).aspx

the windows filtering platform has blocked bind local port

http://blogs.technet.com/b/instan/archive/2009/01/08/the-windows-filtering-platform-has-blocked-a-bind-to-a-local-port.aspx

best regards,

amy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

difference between wuauclt1.exe and wuauclt.exe

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL