DPB Posted March 10, 2016 Report post Posted March 10, 2016 I am running DNS services on three Windows 2012 r2 domain controllers for redundancy. For some reason one of our linux servers keeps being dropped from DNS. I found the event audit log showing that a system userid is doing it, but I can't figure out why. Any ideas? - System - Provider [ Name] Microsoft-Windows-DNSServer [ Guid] {EB79061A-A566-4698-9119-3ED2807060E7} EventID 520 Version 0 Level 4 Task 3 Opcode 0 Keywords 0x4000000002000000 - TimeCreated [ SystemTime] 2016-03-09T20:13:34.650199600Z EventRecordID 670 Correlation - Execution [ ProcessID] 1516 [ ThreadID] 1648 Channel Microsoft-Windows-DNSServer/Audit Computer - Security [ UserID] S-1-5-18 - EventData Type 1 NAME dev7 TTL 0 BufferSize 4 RDATA C0A86452 Zone ZoneScope Default Source 192.168.100.82 Quote Share this post Link to post Share on other sites More sharing options...
arricc Posted March 13, 2016 Report post Posted March 13, 2016 Sounds like DNS scavenging Quote Share this post Link to post Share on other sites More sharing options...