Event ID 520: The system time was changed.
Description | The system time has been changed. The event describes the old and new time. |
Category | System |
The event logs the following information:
Process ID | Unique identifier of the process. |
Process name | Path and name of the process that changed the time. Will usually be rundll32.exe (Control Panel), cmd.exe (Time command) or svchost (if the time was changed by the system in connection with the Windows time synchronization service or NTP) |
Primary user name | Will correspond to local system if changed automatically; otherwise will identify the actual user if changed through control panel or the time command. |
Primary domain | Domain of the user. |
Primary logon ID | Logon ID of the user that correlates to the logon ID in the user's logon session (event ID 528 or 540) |
Client user name | The user name of the user who changed the time |
Client domain | The domain to which the client user belongs to. |
Client logon ID | Logon ID of the user that changed the time. |
Previous time | Time before the event occurred. |
New time | Time after the event occurred. |
Pro tips:
- ADAudit Plus can collect these logs in real time and thus lets you know whenever any change in system time occurs.
- The intuitive reports generated by ADAudit Plus lets you know who changed the system time, when it was changed, and on which machine it was changed. These details can be sent directly to your inbox or as an SMS, with the alerting feature available in ADAudit Plus.
Event 520 applies to the following operating systems:
- Windows server 2000
- Windows server 2003 and XP
Corresponding event in Windows 2008 and Vista - Event 4616
Explore Active Directory auditing and reporting with ADAudit Plus.
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools