More of an art than sience i'm afraid, but you can set the filter view for
the security log to ds and security sources to see if that gives you
something. Also query for the machine name that hosted dns.
It appears that auditing was enabled via policy, but was it also enabled on
the "server name icon" under dns in your snapin (properties of
server/security/advanced/auditing) for whatever group/s may have had
permissions to access/configure dns (administrators, dns operators, etc)
--
David Brandt
Microsoft Corporation
This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send e-mail directly to this alias. This alias is for
newsgroup purposes only.