[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 221
  • Last Modified:

How to log when user restarts PC

I need to log when users reboot this certain PC.  I believe I should go under admin tools - local security policy - local policy - audit policy...but I'm not sure which event to start loging and I don't want to log more than I need.  Is there any documentation on what exacly each of these policies track?  If not, can someone tell me which policy I should log to trap the "restart" or "shutdown" of the PC?
0
j_donald_c
Asked:
j_donald_c
1 Solution
 
Danny ChildIT ManagerCommented:
you can check your System EventLog for event 6005 which shows the Event Log starting up.  This is a good indicator of a reboot.  Also check for 6006 - Event Log Stopping.

Event Type:      Information
Event Source:      EventLog
Event Category:      None
Event ID:      6005
Date:            18/06/2008
Time:            09:12:51
User:            N/A
Computer:      <YourPCname>
Description:
The Event log service was started.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
0
 
j_donald_cAuthor Commented:
Thanks.  That will work.  And now I don't have to worry about loging one of these other areas.
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now