Windows Security Log Event ID 5450

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
Category
 • Subcategory
Policy Change
 • Filtering Platform Policy Change
Type Success
Corresponding events
in Windows 2003
and before
 

5450: A Windows Filtering Platform sub-layer has been changed

On this page

I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Description Fields in 5450

Provider Information:

  •    ID:  %1
  •    Name:  %2

Callout Information:

  •    ID:  %3
  •    Name:  %4
  •    Type:  %5
  •    Run-Time ID: %6

Layer Information:

  •    ID:  %7
  •    Name:  %8
  •    Run-Time ID: %9

Supercharger Free Edition


Supercharger's built-in Xpath filters leave the noise behind.

Free.

 

Examples of 5450

The following callout was present when the Windows Filtering Platform Base Filtering Engine started.

Provider Information:

   ID:  %1
   Name:  %2

Callout Information:

   ID:  %3
   Name:  %4
   Type:  %5
   Run-Time ID: %6

Layer Information:

   ID:  %7
   Name:  %8
   Run-Time ID: %9

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!