User Logon ID

G

Guest

I would like to record User, Computer, and Logon time for each user loging
into our W2K, single DC, server. Something like "net sessions" but recording
just the logon times. The Security Event Viewer seems to capture multiple
events when I ask for "success audit of Logon/Logoff" events. My ultimate
objective is to create a managment report with just the essential logon
identification information.
 
S

Steven L Umbach

Logging onto the domain or just the domain controller?? If you want to audit
all user logons to the domain then enable auditing of "account logon events"
in Domain Controller Security Policy. For logons to just the domain
controller enable auditing of logon events in Domain Controller Security
Policy. It is the nature of Windows auditing to record a lot of apparently
multiple identical events for logons [don't ask me why]. There is no built
in quick and easy way to generate nice concise reports. You may want to look
at a third party program like S.E.L.M. as shown at the link below. They
offer a free trial of it.--- Steve

http://www.gfi.com/lanselm/
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top