861
Security
Detailed Tracking
The Windows Firewall has detected an application listening for incoming traffic.
Name: -
Path: C:\WINDOWS\system32\eventsentry_svc.exe
Process identifier: 4840
User account: es_svc
User domain: DMN
Service: Yes
RPC server: No
IP version: IPv4
IP protocol: UDP
Port number: 2594
Allowed: No
User notified: No
The EventSentry service uses Microsoft's LDAP library to resolve GUIDs from Active Directory at startup and during runtime.
The Microsoft LDAP library opens up both a TCP and UDP connection upon initialization and connection to the nearest domain controller.
The port number will be different on different machines and might change during runtime.
This message can safely be ignored.