Microsoft-Windows-Windows Firewall With Advanced Security/Firewall Event ID 2071 & 2097

Marcin Górski 5 Reputation points
2023-12-26T17:14:30.9366667+00:00

Hello,

In the Azure Sentinel Events table, I'm seeing event IDs 2071 and 2097 from Microsoft-Windows-Windows Firewall With Advanced Security/Firewall but I can't find any information about them in the official documentation.

Event ID 2071 occurs on Windows 11, and Event ID 2097 occurs on Windows 10 workstations.

Can you provide detailed information about those event IDs or direct me to find detailed information in the documentation?

Br

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,660 questions
Windows 10 Network
Windows 10 Network
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Network: A group of devices that communicate either wirelessly or via a physical connection.
2,274 questions
Windows Network
Windows Network
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.Network: A group of devices that communicate either wirelessly or via a physical connection.
653 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,221 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Kevin Herrmann 5 Reputation points
    2024-04-05T15:47:43.1833333+00:00

    I was just investigating why task scheduler tasks triggered by events stopped working months ago and found that, in WIndows 10, 2097 is the event for Added Rule (used to be 2004) and 2099 is the event for Modified Rule (used to be 2005), while Delete Rule remains 2006. This thread is the only thing that came up when I Googled this, so it appears undocumented by Microsoft and adding this in case it helps anyone who does likewise.

    1 person found this answer helpful.