Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
4 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 2002 | New Resource Flow | Operational | N |
| 2003 | Resource Flow Closed | Operational | N |
| 2004 | New Resource Flow | Operational | N |
| 2005 | Resource Flow Closed | Operational | N |
Event ID 2002: New Resource Flow
#Description
New Resource Flow.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | |
Protocol UInt8 | Known values
|
RemoteIPAddress Binary | |
LocalIPAddress Binary | |
RemotePort UInt16 | |
LocalPort UInt16 | |
StartTime FILETIME |
Event ID 2003: Resource Flow Closed
#Description
Resource Flow Closed.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | |
Protocol UInt8 | Known values
|
RemoteIPAddress Binary | |
LocalIPAddress Binary | |
RemotePort UInt16 | |
LocalPort UInt16 | |
StartTime FILETIME | |
CloseTime FILETIME |
Event ID 2004: New Resource Flow
#Description
New Resource Flow.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | |
Protocol UInt8 | Known values
|
RemoteIPAddress UInt32 | |
LocalIPAddress UInt32 | |
RemotePort UInt16 | |
LocalPort UInt16 | |
StartTime FILETIME |
Event ID 2005: Resource Flow Closed
#Description
Resource Flow Closed.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionUsedId UInt64 | |
Protocol UInt8 | Known values
|
RemoteIPAddress UInt32 | |
LocalIPAddress UInt32 | |
RemotePort UInt16 | |
LocalPort UInt16 | |
StartTime FILETIME | |
CloseTime FILETIME |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 92765247-03a9-4ae3-a575-b42264616e78
Defined in fwpkclnt.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4647, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.6584, captured 2026-06-02