If the user is logged into a Windows-based system in an AD environment with security event logging enabled, then you should be able to review the Security logs on any of your domain controllers for the answer. Event ID 528 is registered each time a user successfully logs into one of your Windows-based systems. You'll be able to filter for this event and the system name of the destination computer to see who is accessing it. In Windows 2003 or higher, you'll also be able to see the IP address of the system accessing it as well as the username.
You should also check for Event ID 529 to view failed logon attempts for your systems from a security perspective as well.
Hope this helps...
Mike
Main Topics
Browse All Topics





by: FreshwreckagePosted on 2009-10-30 at 08:08:26ID: 25703706
That would be more of a firewall log issue. If you have a logging server, then you could go through your logs there and get a definitive snapshot of who went where.