Solved

Skype Event id 5156 Windows 2008 R2

Posted on 2016-09-04
6
48 Views
Last Modified: 2016-09-10
We have Skype Events id 5156 of audit success in our Windows 2008 R2 each second or each minute. What could be the reason for so many Events id 5156 of Skype? Is there a way to avoid Skype to post so many Events id 5156 on the Event Viewer without damaging works correctly ? Because is not comfortable be filled of garbage each second. This is the example of the Event id where xxx.xxx.xxx.xxx is our static IP:

The Windows Filtering Platform has permitted a connection.

Application Information:
      Process ID:            5772
      Application Name:      \device\harddiskvolume1\program files (x86)\skype\phone\skype.exe

Network Information:
      Direction:            Outbound
      Source Address:            xxx.xxx.xxx.xxx
      Source Port:            12936
      Destination Address:      157.56.52.35
      Destination Port:            40030
      Protocol:            17

Filter Information:
      Filter Run-Time ID:      215063
      Layer Name:            Connect
      Layer Run-Time ID:      48


Sometimes there are events of audit failed but never stops posting.

Thank you
0
Comment
Question by:Alex E.
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 18

Expert Comment

by:awawada
ID: 41784108
This is caused because of your Security Auditing policy.

Link

So it is a normal behavior and you need not to worry. Event ID 5156 means that the Firewall is allowing a connection to host.
0
 

Author Comment

by:Alex E.
ID: 41784119
Ok I understand is not bad but is there a way to get rid off of this events? We ask because sometimes we need to monitor Event viewer for other things and like there are thousands of other that kind of events is impossible take a look there.

With get rid off I mean to just remove Skype.exe to be audited the rest of the system is ok just Skype.exe is the issue and filter just for Skype to pos Event id 5156 or 5157 would be wonderful. Any ideas?


Thank you
0
 
LVL 18

Expert Comment

by:awawada
ID: 41784212
Do you use Windows Firewall?
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 

Author Comment

by:Alex E.
ID: 41784648
Yes we use of course but we don't want to block the Skype just that events id 5156 and 5157 for Skype only from event viewer.
0
 

Accepted Solution

by:
Alex E. earned 0 total points
ID: 41785060
We solved but we decided for create a custom view in event viewer and then filter that kind of events via XML like this. In that way the Security events of Windows is untouched and the custom view is the one with the filtering. We post just the final XML just in case to other person helps:

<QueryList>
  <Query Id="0" Path="Security">
    <Select Path="Security">*</Select>
    <Suppress Path="Security">*[System[(EventID=5156)]] and *[EventData[Data[@Name='Application'] and (Data ='\device\harddiskvolume1\program files (x86)\skype\phone\skype.exe')]]</Suppress>
    <Suppress Path="Security">*[System[(EventID=5157)]] and *[EventData[Data[@Name='Application'] and (Data ='\device\harddiskvolume1\program files (x86)\skype\phone\skype.exe')]]</Suppress>
  </Query>
</QueryList>

Open in new window


Thank you anyway
0
 

Author Closing Comment

by:Alex E.
ID: 41792499
Thank you
0

Featured Post

The Ultimate Checklist to Optimize Your Website

Websites are getting bigger and complicated by the day. Video, images, custom fonts are all great for showcasing your product/service. But the price to pay in terms of reduced page load times and ultimately, decreased sales, can lead to some difficult decisions about what to cut.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to security, close monitoring is a must. According to WhiteHat Security annual report, a substantial number of all web applications are vulnerable always. Monitis offers a new product - fully-featured Website security monitoring and pr…
There is a lot to be said for protecting yourself and your accounts with 2 factor authentication.  I found to my own chagrin, that there is a big downside as well.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question