If auditing of account management for success is enabled in Domain
Controller Security policy you should see an event ID 645 in the security
log of the domain controller that created the user account. You can use the
free Event Comb from Microsoft to search security logs for specific Event
IDs and text strings such as computer/user names. --- Steve

What is the Event created when a computer is joined to the domain and
if none is made by default how do I set it to make one.