EventNeed to configure Change Auditor to audit domain events across multiple domains/forests.
Change Auditor Coordinators installed across non-trusted Forests are designed to write events to the same database (using SQL Authentication). This allows Reporting, Searching, and Alerting on events that occur in each Forest in the environment, from a single management console.
Please review "Multi-Forest Deployments" in the ChangeAuditor Install Guide.pdf which is part of the Documents folder included with your ChangeAuditor download or online here:
https://support.quest.com/technical-documents/change-auditor/installation-guide/12
The following must be in place for multi-forest deployments:

The following configurations can be shared across forests regardless of the forest trust level:
The following configurations can be shared when a two-way trust exists:

Change Auditor clients do not connect directly to the SQL database. Instead, the coordinator to which the client is connected processes search results and change requests. Clients can connect to any coordinator if the logged on user is a member of either the ChangeAuditor Administrators — <InstallationName> or the ChangeAuditor Operators — <InstallationName> group in the respective forest.

For licensing considerations, refer to the following KB article:
https://support.quest.com/kb/4254797