Announcement

Collapse
No announcement yet.

Need to Audit a users logins and logouts Per Day

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Need to Audit a users logins and logouts Per Day

    We have 4 TS servers that our users use to login to run our business application. We use Server 2008 and have a GPO to use the TS Broker to distribute the load.
    I had a request to audit a users logins for the day.
    When I went to the event viewer > Windows Logs > Security and created a filter to look between the certain days and only displayed Logon and Logoff for the users. However when I run the Find for the specific user, there are several Logoff and logons right around each other. For example - there is a logoff at 2:37 and then a logoff at 2:36 and then one for 2:35 and then there are some logon for 2:34, 2:33 and then a logoff at 12:33, 12:34, 12:37 and then logon 12:15, 12:17 and 12:18. There are several audits throughout the day like this. The only good thing is there is a Login in the morning and then a final logout at the end of the day.
    I looked at the different methods to filter and could not see one that would help reduce the amount of entries. I was guessing that the logon/logoff were due to the session locking during the day.
    Is there a right way to check out a users logon/logoff?
    Thanks,

  • #2
    Re: Need to Audit a users logins and logouts Per Day

    Firsy, I recommanded you to buy some SIM/SOC like Quest InTrust Plug-in for Active Directory.
    If you like to work hard, you can use lof parser or even logon/lofoff script to add a time stamp
    to the logon audit.
    Best Regards,

    Yuval Sinay

    LinkedIn: https://www.linkedin.com/in/yuval14, Blog: http://blogs.microsoft.co.il/blogs/yuval14

    Comment


    • #3
      Re: Need to Audit a users logins and logouts Per Day

      Thanks, I'll take a look at the Quest product.

      Comment

      Working...
      X