Firewall Rule Add
Firewall Rule Add
Configuration
query
EventID:2004
config
Key | Value — | — type | aggregation-v1 query | EventID:2004 streams | [5f74fe0891d2ba1b645adb8d] conditions | {expression:null} search_within_ms | 3600000 execute_every_ms | 3600000
Windows Windows Firewall
If client workstations are taking advantage of the built-in host-based Windows Firewall, then there is value in collecting events to track the firewall status.
Last modified
December 31, 1969