Skip to content

Track DNS records changes

Steps:

 

  • Open Event Viewer
  • In Event Viewer window, go to Windows Logs –>Security logs.
  • Click on Filter current log under Action in the right panel.
  • Open Saved Log... 
Create Custom View... 
Import Custom View... 
Clear Log... 
Filter Current Log... 
Clear Filter 
Properties 
Find 
Save Filtered Log File As... 
Attach a Task To this Log... 
Save Filter to Custom View... 
Refresh 
Help 
4662. Microsoft Windows sec 
Event Properties
  • Search for Event ID 4662 that identifies DNS record changes.
  • Filter Current Log 
Filter XML 
Logged: 
Event level: 
@ By Igg 
By source 
Any time 
Critical 
Ecror 
Event logs: 
Event sources: 
Warning 
Verbose 
Information 
ecurity 
Includes/ExcIudes Event IDs: Enter ID numbers and/or ID ranges separated by commas. To 
exclude criteria, type a minus sign first. For example 
lask category: 
Keywo rds: 
Computer(s): 
Users> 
<AII Computer" 
Clear 
Cancel
  • You can double-click on the event to view Event Properties.