#windows-auditing
2 articles
Windows Events2
Event 4948
Microsoft-Windows-Security-Auditing
Windows EventInformation
Windows Event ID 4948 – Microsoft-Windows-Security-Auditing: IPsec Main Mode Security Association Established
Event ID 4948 indicates successful establishment of an IPsec Main Mode security association between two endpoints, confirming secure tunnel creation for encrypted network communications.
March 1812 min
Event 4947
Microsoft-Windows-Security-Auditing
Windows EventInformation
Windows Event ID 4947 – Microsoft-Windows-Security-Auditing: IPsec Policy Agent Service Started
Event ID 4947 indicates the IPsec Policy Agent service has successfully started on the system. This security audit event confirms IPsec policy enforcement is active and ready to secure network communications.
March 189 min