Folks, on one of the servers I manage, apparently someone had disabled some network components on a network interface and then re-enabled them 10 minutes later. Unfortunately this is a server that has a dozen admins (application dev types -- they're the customer and they are aware of the security ramifications). I checked the event logs for eventids 577/578 , but I wasn't able to find any events logged. Does anyone know if there is a way to audit changing of network components or a means by which I can log this activity. Thanks.