Auditing User logon and logoff, from the event logs on the domain controllers

From: Paul (pwilkins_at_utk.edu)
Date: 04/08/04


Date: 8 Apr 2004 11:48:57 -0700

I'm trying to build statistics on computer lab usage based on the log
on, log off events registered on AD domain controllers.

On individual machines it's pretty easy to determine what's a logon
and what's a logoff. Logon is event id 528, type 2 and logoff is 538
type 3. Getting that same info from the DC's appears more
complicated. 528 applies to only local logons, so can't use that.
I've found that anyone logging on always generates an event id 673, or
kerberos ticket granted. But what about logoffs? Logging off
generates 538's, but the problem is that I see a bunch a 538's when a
users logs in too. Is there a way to accuratly figure out when
someone logs off?



Relevant Pages

  • Re: Active Directory Audit logs
    ... Most logging of account related ... events (logon, logoff etc) is done on the default domain controllers OU so ...
    (microsoft.public.win2000.active_directory)
  • NTFRS error id: 13508
    ... I have several domain controllers, and all are logging this error when trying ... to replicate with one particular dc. ... DNS is fine and I have recreated the ...
    (microsoft.public.win2000.active_directory)
  • Re: logon problem
    ... Security Policy if you want them to access the domain controllers. ... > company who will be logging in remotely. ... > access one server and multiple domain controllers. ... > is no problem logging on to the server with the user ...
    (microsoft.public.win2000.security)
  • problem
    ... support company who is logging in remotely. ... to have access to one server and our domain controllers. ... There is no problem logging on to the server but when they ...
    (microsoft.public.access.security)
  • logon problem
    ... company who will be logging in remotely. ... access one server and multiple domain controllers. ... is no problem logging on to the server with the user ...
    (microsoft.public.win2000.security)