Windows Security Log Event ID 5444
        
        
        
        
        
    
    
    
        
	
		| Operating Systems | 
                            Windows 2008 R2 and 7 
                        
                            Windows 2012 R2 and 8.1 
                        
                            Windows 2016 and 10 
                        
                            Windows Server 2019 and 2022 
                         | 
	
		
                    Category  • Subcategory | Policy Change                   • Filtering Platform Policy Change | 
	
		| 
                    Type
                 | 
                            Success    
                         | 
	
		
                    Corresponding events 
                    in Windows
                    2003  and before | 
                     
                 | 
	
     
    
        5444: The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started
    
    
    
        On this page
    
    
    This event is logged for sub-layer of each WFP provider at startup.  For more information on WFP and providers see 5442.
A sublayer is a collection of filters assigned to a layer within WFP.  For more information on the sub-layer fields of this event see the FWPM_SUBLAYER0 structure in MSDN.
This event does not indicate a change - it just documents the providers present at the time of startup.
Free Security Log Resources by Randy 
    
    
        
                    
    - Provider ID: Globally unique identifier of the provider.
 
    - Provider Name: Name of the provider.
 
    - Sub-layer ID: GUID of sub-layer.
 
    - Sub-layer Name:
 
    - Sub-layer Type: Usually "Persistent" or "Not Persistent".
 
    - Weight:  Relative weight for filter arbitration.
 
        
            
                Setup PowerShell Audit Log Forwarding in 4 Minutes