A warning with Event ID 3006 is repeatedly logged in the Application event log on a Domain Controller.
The event message states:
“An error occurred while reading the event logging record. The specified control code is 425263208. The return code from ReadEventLog is 87.”
Customers want to confirm whether this event is related to Change Auditor and whether any corrective action is required.
This event is generated by the Change Auditor Agent (EvntAgnt) when it encounters an intermittent issue while reading a Windows Event Log record using the Windows ReadEventLog API.
The return code 87 (Invalid parameter) is a known Windows API response that may occur due to:
High event log activity (commonly observed on Domain Controllers)
Rapid event log rotation or truncation
Temporary contention within the Windows Event Log service
This behavior is intermittent and generally benign.
No action is required if:
The Change Auditor Agent remains connected
Events continue to appear normally in the Change Auditor client
No auditing gaps or functional issues are observed
Recommended best practices:
Ensure Change Auditor Coordinators and Agents are running the same version
Confirm normal auditing functionality from the Change Auditor client
If the warning appears frequently, restarting the Change Auditor Agent service may reduce its occurrence
If missing events or agent connectivity issues are observed, further investigation may be required.