Event ID 4616
The system time was changed
The system time was changed.
Subject:
Security ID: %1
Account Name: %2
Account Domain: %3
Logon ID: %4
Process Information:
Process ID: %7 [Windows 7+]
Name: %8 [Windows 7+]
Previous Time: %5
New Time: %6
This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer.
This event generates every time system time was changed.
This event is always logged regardless of the "Audit Security State Change" sub-category setting.
You will typically see these events with “Subject\Security ID” = “LOCAL SERVICE”, indicating a normal time correction action.
Name |
Field |
Insertion String |
OS |
Example |
|
|
Security ID |
SubjectUserSid |
%1 |
Any |
S-1-5-21-3457937927-2839227994-823803824-1104
|
|
Account Name |
SubjectUserName |
%2 |
Any |
UserName
|
|
Account Domain |
SubjectDomainName |
%3 |
Any |
DOMAIN
|
|
Logon ID |
SubjectLogonId |
%4 |
Any |
0x48f29
|
|
Previous Time |
PreviousTime |
%5 |
Any |
2015-10-09T05:04:30.000941900
|
|
New Time |
NewTime |
%6 |
Any |
2015-10-09T05:04:30.000000000Z
|
|
Process ID |
ProcessId |
%7 |
Win7/2008R2+ |
0x1074
|
|
Name |
ProcessName |
%8 |
Win7/2008R2+ |
C:\Windows\WinSxS\amd64\_microsoft-windows-com-surrogate-core\_31bf3856ad364e35\_6.3.9600.16384\_none\_25a8f00faa8f185c\dllhost.exe
|
SID of account that requested the “change system time” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event.
Note A security identifier (SID) is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group.
The name of the account that requested the “change system time” operation.
"Subject’s domain or computer name. Formats vary, and include the following:
Domain NETBIOS name example: DOMAIN
Lowercase full domain name: domain.local
Uppercase full domain name: DOMAIN.LOCAL
For some well-known security principals, such as LOCAL SERVICE or ANONYMOUS LOGON, the value of this field is “NT AUTHORITY”.
For local user accounts, this field will contain the name of the computer or device that this account belongs to, for example: “ComputerName”."
Hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, “4624: An account was successfully logged on
Previous time in UTC time zone. The format is YYYY-MM-DDThh:mm:ss.nnnnnnnZ:
Y - years
M - months
D - days
T - the beginning of the time element, as specified in ISO 8601.
h - hours
m - minutes
s - seconds
n - fractional seconds
Z - the zone designator for the zero UTC offset. "09:30 UTC" is therefore represented as "09:30Z". "14:45:15 UTC" would be "14:45:15Z".
New time that was set in UTC time zone. The format is YYYY-MM-DDThh:mm:ss.nnnnnnnZ:
Y - years
M - months
D - days
T - the beginning of the time element, as specified in ISO 8601.
h - hours
m - minutes
s - seconds
n - fractional seconds
Z - the zone designator for the zero UTC offset. "09:30 UTC" is therefore represented as "09:30Z". "14:45:15 UTC" would be "14:45:15Z".
Hexadecimal Process ID of the process that changed the system time. Process ID (PID) is a number used by the operating system to uniquely identify an active process.
Full path and the name of the executable for the process.
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Security State Change"
LEFT/RIGHT arrow keys for navigation
Back to List