I answered ALLOW to a firewall prompt too fast before I read it. So, when I went to the logs to see what I had allowed, I noticed no allows are being logged at all. Only block actions. How can I see the allows?




Usually, allowed applications aren’t logged. If you go to Global rules, and right-click an allow-rule, you’ll have the option to “Create an alert if this rule is fired”. You’ll need to have a rule that allows TCP/UDP to go Out or In for this to work. Then the rule will allow the application to connect, and it’ll be logged in Firewall events.