See steps below to troubleshoot this issue:
1.- Verify that the operation change details and that the ChangeAuditor integration policy are applied in the "Active roles Admin Service" event viewer entry:
2.- Verify the details sent from Active Roles are correct:
2.1.- Enable the "Administration Service" Verbose logging.
2.2.- Make a change via the ARS Console.
2.3.- Disable the "Administration Service" Verbose logging
2.4.- Open the new DS.log file using the ARS Log Viewer.
2.5.- View the "Raw log records" and search by "ChangeAuditorDDC", once you find this specific request, you will be able to find the following details:
- DomainName\USerName of the initiator
- Initiator SID
- Domain Controller where the details were sent over
3.- Verify the information received by the ChangeAuditor Agent running in the Domain Controller where the ARS Admin service has sent the details over:
3.1.- Open the ChangeAuditor Agent Status to verify the Agent appears running and connected to the Coordinator Server.
3.2.- Open the ChangeAuditor Agent Log:
3.3.- Search by "Initiator:":
3.4.- Verify the initiator details and time are correct: