Compatible Support Forums: Server Event viewer interpretation (Logon/Logoff)

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Server Event viewer interpretation (Logon/Logoff)

#1 User is offline   rwilliams3 

  • stranger
  • Group: Members
  • Posts: 2
  • Joined: 28-January 03

Posted 28 January 2003 - 08:40 PM

I have been asked by management to provide a report displaying when users logon in the morning and logoff when they are leaving.

I've looked in the Event Viewer/Security Log and identified event ID 540 as Logon & 538 as Logoff, but there are multiple instances for each?

For example, I see event ID 540 for user:Wilber$ logging in at 7:49 am, 8:14, 8:28, 8:44, etc...

Same for event ID 538.

How can I best filter these extra entries out and create a useful report?

Thanks,

Russell
:x
0

#2 User is offline   DosFreak 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3885
  • Joined: 04-February 00

Posted 28 January 2003 - 08:56 PM

Extra entries? These are the times that the user logged on/logged off. I'm assuming that the user locked/unlocked their workstation and logged back on again. The times sound about right. For proper auditing you NEED these times logged.
0

#3 User is offline   Mr.Guvernment 

  • veteran
  • Group: Members
  • Posts: 1441
  • Joined: 04-January 01

Posted 28 January 2003 - 08:59 PM

could very well be he has logged in and out, multiple times,

or do u simply want to know when he was in the first time, and logged out the last time?

you can sort it by time / date i beleive.

Management woud likey want ALL times - they are probably seeing how often users are away from the stations when they should not be.
0

#4 User is offline   rwilliams3 

  • stranger
  • Group: Members
  • Posts: 2
  • Joined: 28-January 03

Posted 28 January 2003 - 10:00 PM

They only need the first logon time in the morning and the last logoff time in the afternoon. Kinda like a punch-clock time keeper.

Some of the logon/logoff events happen every 2 or 3 minutes. Don't think someone would be locking/unlocking their workstation that frequently?

In Domain Security Policy/Local Policies/Audit Policy I have two items logging Success/Failures. They are:
1. Audit account logon events
2. Audt logon events

What's the difference?

RW
0

#5 User is offline   DS3Circuit 

  • old hand
  • Group: Members
  • Posts: 739
  • Joined: 11-December 02

Posted 29 January 2003 - 01:04 AM

1. Audit account logon events is when a domain controller receives a request to validate a user account. See article http://support.microsoft.com/support/kb/articles/q174/0/73.asp

2. Audit logon events is when a user logs on or off, or makes or cancels a network connection.

Auditing is a great way to detect random password hacks and or stolen user credentials with those 2 audits.
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users