Event ID 5156
Posted: Mon May 18, 2020 10:25 am
Our NLS get bogged down ever few days with event ID 5156. It appears that when a log is sent the NLS it created a 5156 event. Then sending the 5156 log creates another and so on and so on.
We have the following in our nxlog config but we are still receiving the logs at the bottom of this post in NLS.
Exec if ($EventID == 5156 AND ($DestinationPort == 514 OR $DestinationPort == 3515)) drop();
The Windows Filtering Platform has permitted a connection.
Application Information:
Process ID: 3772
Application Name: \device\harddiskvolume4\program files (x86)\nxlog\nxlog.exe
Network Information:
Direction: Outbound
Source Address:
Source Port: 49694
Destination Address:
Destination Port: 3515
Protocol: 6
Filter Information:
Filter Run-Time ID: 67911
Layer Name: Connect
Layer Run-Time ID: 48
We have the following in our nxlog config but we are still receiving the logs at the bottom of this post in NLS.
Exec if ($EventID == 5156 AND ($DestinationPort == 514 OR $DestinationPort == 3515)) drop();
The Windows Filtering Platform has permitted a connection.
Application Information:
Process ID: 3772
Application Name: \device\harddiskvolume4\program files (x86)\nxlog\nxlog.exe
Network Information:
Direction: Outbound
Source Address:
Source Port: 49694
Destination Address:
Destination Port: 3515
Protocol: 6
Filter Information:
Filter Run-Time ID: 67911
Layer Name: Connect
Layer Run-Time ID: 48