Share via

Seeing a Network security event with Protocol 0

LM 0 Reputation points
2023-09-17T02:36:29.18+00:00

Seeing the following security event with Protocol 0.

Want to know why we are seeing the protocol as 0 here.

Event[0]:
  Log Name: Security
  Source: Microsoft-Windows-Security-Auditing
  Date: 2023-09-15T12:06:28.694
  Event ID: 5156
  Task: Filtering Platform Connection
  Level: Information
  Opcode: Info
  Keyword: Audit Success
  User: N/A
  User Name: N/A
  Computer: XLSA
  Description: 
The Windows Filtering Platform has permitted a connection.

Application Information:
	Process ID:		2892
	Application Name:	\device\harddiskvolume3\windows\system32\svchost.exe

Network Information:
	Direction:		Inbound
	Source Address:		10.75.131.147
	Source Port:		137
	Destination Address:	10.75.131.255
	Destination Port:		137
	Protocol:		0                        <------ Why showing 0 ?

Filter Information:
	Filter Run-Time ID:	165473
	Layer Name:		Receive/Accept
	Layer Run-Time ID:	44
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.