Security Log

anonymous_at_discussions.microsoft.com
Date: 08/11/04


Date: Wed, 11 Aug 2004 10:57:28 -0700

I have set a "Account Logon Event" local policy on a
Win2003 dc to audit sucessful attempts to logon to our
Domain from both inside and outside(vpn-ras) the
firewall. When I check the security log in event viewer
it shows users logging on and off but the time periods
are totally wrong. IE. I logged on this morning at
6:00amMTN and have not logged off, yet the security log
shows an event 680 me logging in 8 times at different
intervals. There must be a better way to do this or I am
viewing the log incorrectly.

Appreciate any feedback.

EARLIER POST:

I have setup a local security policy on a win 2003 dc to
audit for "Successful Attempts" and have noticed that
when I check the Security tab in event viewer it shows
event id's 540 (Successful logon) and 538 (Successful
logoff)minutes apart for users when they have been logged
on for hours......I would expect to see an event when
they successfully logon anf then another when they log
off...what I see is continous logons and logoffs minutes
apart throughout the day.

Am I missing something here?



Relevant Pages