WFP is a Windows Filtering Platform is a development platform and not a firewall itself where network data can be filtered and also modified before it reaches its destination
If Qlik Sense is not excluded from WFP, the Windows event logs showing hundreds of 5152 events are recorded on a server every minute, making it slow and sometime inaccessible, even when processor utilisation is less than 50%
Here is an explanation of a 5152 event:
This is an issue outside of product applied in the network. In situations such as this we advise to see:
1. Where exactly in the network WFP has been applied and why ?
2. When it has been applied ? See if the date that it was applied it matches with the date when the event logs audit failure notifications started to get generated
3. If it can be temporarily disabled for testing purposes
4. If it can be modified to allow applications by application id or process id exclusions as per article below
The link below shows information and sample code demonstrates how to add a filter that evaluates by user or application ID.