FwpmNetEventEnum5 - NtDoc

Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers
// fwpmk.h

NTSTATUS FwpmNetEventEnum5(
  [in]  HANDLE          engineHandle,
  [in]  HANDLE          enumHandle,
  [in]  UINT32          numEntriesRequested,
  [out] FWPM_NET_EVENT5 ***entries,
  [out] UINT32          *numEntriesReturned
);
View the official Windows Driver Kit DDI reference

NtDoc

No description available.

Windows Driver Kit DDI reference (nf-fwpmk-fwpmneteventenum5)

Description

The FwpmNetEventEnum5 function returns the next page of results from the network event enumerator.

Parameters

engineHandle [in]

Handle for an open session to the filter engine. Call FwpmEngineOpen0 to open a session to the filter engine.

enumHandle [in]

Handle for a network event enumeration created by a call to FwpmNetEventCreateEnumHandle0.

numEntriesRequested [in]

The number of enumeration entries requested.

entries [out]

Addresses of enumeration entries.

numEntriesReturned [out]

The number of enumeration entries returned.

Return value

Return code/value Description
ERROR_SUCCESS
0
The network events were enumerated successfully.
FWP_E_NET_EVENTS_DISABLED
0x80320013
The collection of network diagnostic events is disabled. Call FwpmEngineSetOption0 to enable it.
FWP_E_* error code
0x80320001—0x80320039
A Windows Filtering Platform (WFP) specific error. See WFP Error Codes for details.
RPC_* error code
0x80010001—0x80010122
Failure to communicate with the remote or local firewall engine.
Other NTSTATUS codes An error occurred.

Remarks

If the numEntriesReturned is less than the numEntriesRequested, the enumeration is exhausted.

The returned array of entries (but not the individual entries themselves) must be freed by a call to FwpmFreeMemory0.

A subsequent call that uses the same enumHandle parameter returns the next set of events following those in the current entries buffer.

FwpmNetEventEnum5 returns only events that were logged prior to the creation of the enumHandle parameter. See Logging for more information.

FwpmNetEventEnum5 is a specific implementation of FwpmNetEventEnum. See WFP Version-Independent Names and Targeting Specific Versions of Windows for more information.

See also