I have a request from our boss to provide the times a few users have logged on and off of their computers. The problem is I'm having a real tough time looking through the events and being able to tell what's an actual logon/logoff or just accessing a network share. I've tried Microsoft's Event Comb, but I'm still not sure what to look for. Can anyone provide any insight on the best way to do this? I do know there are 3rd party utilities, but at the current time those aren't really an option.