Windows Security Log Event ID 4947

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
Category
 • Subcategory
Policy Change
 • MPSSVC Rule-Level Policy Change
Type Success
Corresponding events
in Windows 2003
and before
851 , 852  

4947: A change has been made to Windows Firewall exception list. A rule was modified

On this page

Exceptions define traffic that bypasses other Windows Firewall rules.

Profile Changed: Domain, Private, Public, All

Free Security Log Resources by Randy

Description Fields in 4947

Modified Rule:

Name and ID of the rule modified.
These rules are defined in Group Policy and in the Windows Firewall with Advanced Services MMC console

Supercharger Free Edition

 

Examples of 4947

A change has been made to Windows Firewall exception list. A rule was modified.

Profile Changed: -

Modified Rule:

   Rule ID: WMI-RPCSS-In-TCP
   Rule Name: @FirewallAPI.dll,-34252

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Additional Resources

    Go To Event ID:

    Security Log
    Quick Reference
    Chart
    Download now!