Security Compliance

Tune out Windows Filtering Platform on SEM and on a Windows agent

This article describes how to tune out Windows Filtering Platform (WFP) on SEM and on a Windows agent. WFP is a new application in Windows 7 and Windows 8 and Server 2008/2012 that logs firewall and IPsec related events to the System Security Log. These alerts represent accepted background alerts on SEM and consume additional resources on SEM while it processes these events. They are not necessary in an optimized SEM deployment.

First published date

10/17/2018 10:28 PM

Last published date

10/17/2018 10:28 PM

Overview

This article describes how to tune out Windows Filtering Platform (WFP) noise on Security Event Manager (formerly Log & Event Manager) and on a Windows agent. WFP is a new application in Windows newer operating systems, starting with Windows Vista, that logs firewall and IPsec related events to the Security Event Log. These alerts (events) provide no value for auditing, represent noise. In addition, they consume additional resources on SEM. Once SEM has been upgraded to version 6.2.0 or newer, SEM agent version 6.2.0 will drop these events at the Windows computer so that SEM never receives these events.

Please note, on environment:
  • WFP does not exist if SEM agent is 6.2.0 or newer.
  • Windows 7, 8, 8.1, 10
  • Windows Server 2008, 2008-R2, 2012, 2012-R2, 2016

Product section

Security Event Manager

Resolution

Modify the SEM Alert Distribution Policy 

  1. Open SEM Console and log into your SEM Manager from the Manage > Appliances view.
  2. Next to your SEM Manager, click the gear icon, and then select Policy.

    This is the Event Distribution Policy.

  3. Locate the alerts you want to disable by either browsing the Alert Taxonomy or using the search box under Refine Results.

    You can locate all the alerts listed below by typing Windows Security in the search box.

  4. Select or clear the check boxes in Console, Database, Warehouse or Rules, as appropriate.
    • Clear the Console check box to prevent your SEM Manager from showing the alerts in your SEM Console.
    • Clear the Database check box to prevent your SEM Manager from storing the alerts in your SEM database.
    • Clear the Warehouse check box to prevent your SEM Manager from sending the alerts to an independent database warehouse.
    • Clear the Rules check box to prevent your SEM Manager from processing the alerts against your SEM rules.
    • Select any check box to enable processing of the alerts for any of the four levels listed above. 
  5.  If you want to save your changes and keep working, click Apply, or click OK if you want to save your changes and exit the Alerts Distribution Policy window.

Table  of Alerts with Security Auditing Provider SIDs

The Provider SID value in the following alerts match the format, Windows Security, Auditing Event ID,  where Event ID is one of the Windows Event ID listed below.

Alert NameWindows Event ID
TCPTrafficAudit    5152, 5154, 5156, 5157, 5158, 5159  
IPTrafficAudit5152, 5154, 5156, 5157, 5158, 5159
UDPTrafficAudit5152, 5154, 5156, 5157, 5158, 5159
ICMPTrafficAudit5152, 5156, 5157, 5158, 5159
RoutingTrafficAudit  5152, 5156
PPTPTrafficAudit5152

Table of Description by Event ID

Event ID Brief Description 
5152Windows Filtering Platform blocked a packet.
5154Windows Filtering Platform permitted an application or service to listen on a port for incoming connections.
5156Windows Filtering Platform allowed a connection.
5157Windows Filtering Platform blocked a connection.
5158Windows Filtering Platform permitted a bind to a local port.
5159Windows Filtering Platform blocked a bind to a local port.

Additional Suggested Settings

Set the following subcategories to No Auditing to tune Windows Advanced Audit Policy logging for LEM implementation:

  • Logon/Logoff > Audit IPsec Extended Mode
  • Logon/Logoff > Audit IPsec Main Mode
  • Logon/Logoff > Audit IPsec Quick Mode
  • Object Access > Audit Filtering Platform Connection
  • Object Access > Audit Filtering Platform Packet Drop
  • Policy Change > Audit Filtering Platform Policy Change
  • System > Audit IPsec Driver

Set a WFP subcategory to No Auditing using Group Policies 

  1. Navigate to Control Panel > Administrative Tools, and then open Group Policy Management.
  2. Open Group Policy Management Editor for the domain policy you want to edit. For example, click Default Domain Policy, and then click Action > Edit.
  3. Under Computer Configuration, navigate to Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies.
  4. Click each policy under this node to view and edit its subcategories.
  5. In the right pane, click the subcategory you want to edit, and then click Action > Properties.
  6. On the Policy tab, select Configure the following audit events. Do not select Success or Failure.
    Note: To edit WFP auditing using local policy instead, open Administrative Tools > Local Security Policy, and expand Advanced Audit Policy Configuration.

Additional Resources 

For additional information about Advanced Audit Policy Configuration, see the Microsoft TechNet article, Advanced Security Auditing FAQ  (© 2018 Microsoft, available at https://www.microsoft.com/en-us/, obtained on December 17, 2018)

For information about tuning standard Windows audit policies for SEM implementation on a non-WFP computer, see:

If you are required to log these WFP events, contact SolarWinds support for a connector that reads and forwards the WFP events.

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.