Event ID: 4616

The system time was changed

The system time was changed.

    Security ID:        %1
    Account Name:       %2
    Account Domain:     %3
    Logon ID:           %4

Process Information:
    Process ID:         %7 [Windows 7+]
    Name:               %8 [Windows 7+]

Previous Time:          %5
New Time:               %6

This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer.

This event generates every time system time was changed.

This event is always logged regardless of the "Audit Security State Change" sub-category setting.

You will typically see these events with “Subject\Security ID” = “LOCAL SERVICE”, indicating a normal time correction action.

Name Field Insertion String OS Example
Security ID SubjectUserSid %1 Any S-1-5-21-3457937927-2839227994-823803824-1104
Account Name SubjectUserName %2 Any UserName
Account Domain SubjectDomainName %3 Any DOMAIN
Logon ID SubjectLogonId %4 Any 0x48f29
Previous Time PreviousTime %5 Any 2015-10-09T05:04:30.000941900
New Time NewTime %6 Any 2015-10-09T05:04:30.000000000Z
Process ID ProcessId %7 Win7/2008R2+ 0x1074
Name ProcessName %8 Win7/2008R2+ C:\Windows\WinSxS\amd64\_microsoft-windows-com-surrogate-core\_31bf3856ad364e35\_6.3.9600.16384\_none\_25a8f00faa8f185c\dllhost.exe

Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Security State Change"

