Skip to content

Track DNS records changes

Steps:

 

  • Open Event Viewer
  • In Event Viewer window, go to Windows Logs –>Security logs.
  • Click on Filter current log under Action in the right panel.
  • Open Saved Log...
Create Custom View...
Import Custom View...
Clear Log...
Filter Current Log...
Clear Filter
Properties
Find
Save Filtered Log File As...
Attach a Task To this Log...
Save Filter to Custom View...
Refresh
Help
4662. Microsoft Windows sec
Event Properties
  • Search for Event ID 4662 that identifies DNS record changes.
  • Filter Current Log
Filter XML
Logged:
Event level:
@ By Igg
By source
Any time
Critical
Ecror
Event logs:
Event sources:
Warning
Verbose
Information
ecurity
Includes/ExcIudes Event IDs: Enter ID numbers and/or ID ranges separated by commas. To
exclude criteria, type a minus sign first. For example
lask category:
Keywo rds:
Computer(s):
Users>
<AII Computer"
Clear
Cancel
  • You can double-click on the event to view Event Properties.