Hi,
An event ID 633 is generated when a user is removed from a particular security group in the domain..it also shows the domain admin ID which was used to remove it..Is there any way to find out the name of the machine or its IP address from where the domain admin ID was used to remove the user from the group ?
any suggestion would be of great help....

