How to audit Computers creation/deletion on Active Directory

On security eventlog you can find this eventid that make you able to understand what are going on computers account management:

645 – for Computer account creation

646 – for Computer account change

647 – for Computer account deletion

Here a script to collect this 3 events to a file via powershell.

$date = Get-Date -Format 'yyyyMMdd'
Get-EventLog -logname "Security" | where {$_.eventID -eq 645 -or $_.eventID -eq 646 -or $_.eventID -eq 647} | Select Index,TimeGenerated,EntryType,Source,InstanceID,@{L='Message';E={($_.Message -replace '\s',' ')}} | export-csv -path D:\SecurityLog\eventlog$date.csv
Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s