Microsoft-Windows-Base-Filtering-Engine-Resource-Flows

4 events across 1 channel

EventTitleChannelSample
2002New Resource FlowOperationalN
2003Resource Flow ClosedOperationalN
2004New Resource FlowOperationalN
2005Resource Flow ClosedOperationalN

Event ID 2002: New Resource Flow

#
Provider
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Channel
Operational
Opcode
Info

Description

New Resource Flow.

Message #

New Resource Flow

Fields #

NameDescription
ConnectionUsedId UInt64
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
RemoteIPAddress Binary
LocalIPAddress Binary
RemotePort UInt16
LocalPort UInt16
StartTime FILETIME

Event ID 2003: Resource Flow Closed

#
Provider
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Channel
Operational
Opcode
Info

Description

Resource Flow Closed.

Message #

Resource Flow Closed

Fields #

NameDescription
ConnectionUsedId UInt64
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
RemoteIPAddress Binary
LocalIPAddress Binary
RemotePort UInt16
LocalPort UInt16
StartTime FILETIME
CloseTime FILETIME

Event ID 2004: New Resource Flow

#
Provider
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Channel
Operational
Opcode
Info

Description

New Resource Flow.

Message #

New Resource Flow

Fields #

NameDescription
ConnectionUsedId UInt64
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
RemoteIPAddress UInt32
LocalIPAddress UInt32
RemotePort UInt16
LocalPort UInt16
StartTime FILETIME

Event ID 2005: Resource Flow Closed

#
Provider
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows
Channel
Operational
Opcode
Info

Description

Resource Flow Closed.

Message #

Resource Flow Closed

Fields #

NameDescription
ConnectionUsedId UInt64
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
RemoteIPAddress UInt32
LocalIPAddress UInt32
RemotePort UInt16
LocalPort UInt16
StartTime FILETIME
CloseTime FILETIME

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 92765247-03a9-4ae3-a575-b42264616e78

Defined in fwpkclnt.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4647, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.6584, captured 2026-06-02

Downloads