Windows Security Log Event ID 854

Operating Systems Windows 2003 and XP
CategoryPolicy Change
Type Success
Corresponding events
in Windows 2008
and Vista
4950  

854: The Windows Firewall logging settings have changed

On this page

Windows logs this event when an administrator changes the local policy of the Windows Firewall or a group policy refresh results in a change to the Windows Firewall logging settings.

Free Security Log Resources by Randy

Description Fields in 854

  • Policy origin: Group Policy or Local Policy
  • Profile changed: Standard or Domain

New Settings:

  • Log dropped packets: Enabled or Disabled
  • Log successful connections: Enabled or Disabled

Old Settings:

  • Log dropped packets: Enabled or Disabled
  • Log successful connections: Enabled or Disabled

 

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Examples of 854

The Windows Firewall logging settings have changed.
 
Policy origin: Local Policy
Profile changed: -
New Settings:
     Log dropped packets: Enabled
     Log successful connections: Enabled
Old Settings:
     Log dropped packets: Disabled
     Log successful connections: Disabled

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Additional Resources

    Go To Event ID:

    Security Log
    Quick Reference
    Chart
    Download now!