Solved

Windows Time Service logs

Posted on 2011-09-02
10
322 Views
Last Modified: 2012-05-12
Hi,
I am trying to find out if there is a way to see the activity of Windows Time Service? To be more specific -  time corrections (if any) has occurred in particular date and time.  

Thanks.
0
Comment
Question by:scripun
  • 3
  • 3
  • 2
  • +1
10 Comments
 
LVL 4

Expert Comment

by:LHFoods
ID: 36475130
You can view some activity in the System Event Log of the machine in question.  To see detailed info you will probably have to change the logging parameters for the w32tm service.
0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36475353
Hi,

Time synch plays important role in AD environment, You have provided very short info about your AD environment, server & workstations.

am trying to find out if there is a way to see the activity of Windows Time Service?
Go to event log> system and filter events by w32time source.

PDC emulator role owner's time service should be sync with external time source and all other members should be sync with it.

First of all find out which server is holding PDC Emulator Role by typing "netdom query fsmo"

Once you have find out the PDC role holder server ,Configure PDC role server with External Time Source

How to configure an authoritative time server in Windows Server
http://support.microsoft.com/kb/816042

To check if time sever is working fine give the command "w32tm /resync /rediscover" you will get one information Event in the Event viewer .

After Configuring PDC role server ,configure other member server /workstations in the site to sync the Time with PDC server role

So your Goal is

PDC Server Role :
-----------------------
NtpServer : time.windows.com,0x1
AnnounceFlags : 5
Type : NTP

Other Server & Clients Machine
------------------------------------------
NtpServer : Server name(PDC role holder),0x1 or IP address of PDC role holder server
AnnounceFlags : 10
Type : NT5DS

E.g : ntpserver : PDCservername,0x1 or (IP) xx.xx.xx.xx

Regards,
Abhijitw.
0
 
LVL 37

Expert Comment

by:Gerwin Jansen
ID: 36475379
The W32Time service is logging al its actions in the System Event log, correct.

There's no need to change any parameters, you can see what's happening just fine, just filter on the w32tm service.
0
 

Author Comment

by:scripun
ID: 36475418
@abhijitwaikar
Thanks. I am all good there. Good info though.
@gerwinjansen
I don't see any W32Time service logs there for some reason.
0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36475534
Hi,

I don't see any W32Time service logs there for some reason.
Check the windows time service is started otherwise it does not generate w32time event. Aslo you can try to view by w32tm and net time commands.

Regards,
Abhijitw.

0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 4

Expert Comment

by:LHFoods
ID: 36476097
@gerwinjansen
Successful w32time sync events are not logged by default.  Thus if the onle events you see are that
"The time service is now synchronizing the system time with the time source yourdc.yourdomain.com"
that typically means that the time synch is functioning properly.
0
 
LVL 4

Expert Comment

by:LHFoods
ID: 36476109
This site was pretty informative on logging successfull time changes:
http://www.stevebunting.org/udpd4n6/forensics/timechange.htm
0
 

Author Comment

by:scripun
ID: 36476205
@LHFoods
Thanks. It's still not clear to me if this will occur durring automatic time changes. I like to change w32time events to log more info. Is it posible?
0
 
LVL 37

Accepted Solution

by:
Gerwin Jansen earned 500 total points
ID: 36476257
Hi, according to MS, you can setup logging, described here. I didn't test this personally though.
0
 

Author Comment

by:scripun
ID: 36476289
@gerwinjansen
This should be good for what I need.
Thank you all.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now