Link to home
Start Free TrialLog in
Avatar of nav2567
nav2567Flag for United States of America

asked on

DNS Auditing question

Our default domain controller policy has the "Audit Directory Service Access" enabled and log all success events for group EVERYONE.

We have some missing production DNS records. Exactly where do I look in the event log and what event I can look for in order to determine who removed the DNS records?

Someone who knows please advise.
ASKER CERTIFIED SOLUTION
Avatar of Aard Vark
Aard Vark
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of nav2567

ASKER

Excellent.  Thank you very much!!!