Hello,
After more investigation, it seems that it is the Windows firewall that does
all the events for all the process runing on the computer (hyper-v, rdp,
....)
there is an event enabling the ALE listen v4 layer, ALE listen v4 layer
After that, the same event with the delete of the ALE V4 and V6 Layer.
Thank you
Marc
"Marc Allard" <> wrote in message
news:80031845-66F4-4B64-BF2C-...
> Hello,
>
> I have a very strange problem with Windows server 2008 R2
> Every 2-3 minutes, I receive 40-50 times the event ID 5447
> A windows filtering platform has been changed
>
> SecurityID = Local service
> Account name NT AUTHORITY\LOCAL SERVICE
>
>
> The name is Terminal Services
> I have no idea about what to do, but I have less than 12 hours for the log
> to fill the 20 MB
> Can someone please help me to see what iswrong?
>
> Thank you
> Marc
|