Get the App
SLTechnology News&Howtos  ›  Servers  › 

CS12: customer DC found a large number of Event 5152 logs and asked for help to troubleshoot the cause

Shulou Source: shulou.com Published: 2022-06-03 06:43:11 10月01日 Update

Summary of customer questions:

The customer said that a large number of security logs with an ID of 5152 were found on the domain control, almost 3 per second, and they wanted to give relevant checks.

The log is as follows:

The Windows Filtering Platform has blocked a packet.

Application Information:

Process ID: 0

Application Name:-

Network Information:

Direction: Inbound

Source Address: 0.0.0.0

Source Port: 68

Destination Address: 255.255.255.255

Destination Port: 67

Protocol: 17

Filter Information:

Filter Run-Time ID: 437032

Layer Name: Transport

Layer Run-Time ID: 13

Solution:

And WFP filtering logs are enabled by the customer. Just turn off this logging.

For example:

Close this log using the following command:

Auditpol / set / category: "system" / subCategory: "Filtering Platform Connection" / Failure:Disable

Auditpol / set / category: "system" / subCategory: "Filtering Platform Packet Drop" / Failure:Disable

Then gpupdate / force refreshes the group policy

Tags: Log customer security layer 2 command data method purpose port policy problem firewall analysis audit broadcast inspection summary fire prevention cause help Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno OPPO Reno Shulou Technology Shulou Tech Info Redmi MySQL