Event ID: 4616

The system time was changed

The system time was changed.

Subject:
    Security ID:        %1
    Account Name:       %2
    Account Domain:     %3
    Logon ID:           %4

Process Information:
    Process ID:         %7 [Windows 7+]
    Name:               %8 [Windows 7+]

Previous Time:          %5
New Time:               %6

This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer.
Microsoft Documentation

Event ID - 4616



This event generates every time system time was changed.

This event is always logged regardless of the "Audit Security State Change" sub-category setting.

You will typically see these events with “Subject\Security ID” = “LOCAL SERVICE”, indicating a normal time correction action.



Name Field Insertion String OS Example
Security ID SubjectUserSid %1 Any S-1-5-21-3457937927-2839227994-823803824-1104
Account Name SubjectUserName %2 Any UserName
Account Domain SubjectDomainName %3 Any DOMAIN
Logon ID SubjectLogonId %4 Any 0x48f29
Previous Time PreviousTime %5 Any 2015-10-09T05:04:30.000941900
New Time NewTime %6 Any 2015-10-09T05:04:30.000000000Z
Process ID ProcessId %7 Win7/2008R2+ 0x1074
Name ProcessName %8 Win7/2008R2+ C:\Windows\WinSxS\amd64\_microsoft-windows-com-surrogate-core\_31bf3856ad364e35\_6.3.9600.16384\_none\_25a8f00faa8f185c\dllhost.exe


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Security State Change"
How to enable Windows Auditing



LEFT/RIGHT arrow keys for navigation

Back to List