How to audit Computers creation/deletion on Active Directory

On security eventlog you can find this eventid that make you able to understand what are going on computers account management:

645 – for Computer account creation

646 – for Computer account change

647 – for Computer account deletion

Here a script to collect this 3 events to a file via powershell.

$date = Get-Date -Format 'yyyyMMdd'
Get-EventLog -logname "Security" | where {$_.eventID -eq 645 -or $_.eventID -eq 646 -or $_.eventID -eq 647} | Select Index,TimeGenerated,EntryType,Source,InstanceID,@{L='Message';E={($_.Message -replace '\s',' ')}} | export-csv -path D:\SecurityLog\eventlog$date.csv

