• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 816
  • Last Modified:

event id 540 and 538

We have a couple of users that are generating event id 540 and 538 on our domain controller. We have auditing enabled. When i look at the event logs for either of these users it shows various logon/logoff times even when the user is not at the office and has claimed to have shut down their machine. This came up because they claimed to have shut down their pc at night (not log off) but when they came in their login screen was up and email was open. I'm trying to sift through my event logs to give the manager their login/logout times but there are quite a few all through the night. That user does not have remote access so trying to ascertain which are legitimate login/logout times is difficult especially with so many event id 540 and 538 entries. Can you clear this up for me and explain what i may need to look out for?
Frank Ferrer
Frank Ferrer
1 Solution
Justin OwensITIL Problem ManagerCommented:
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: Microsoft Azure 2017

Azure has a changed a lot since it was originally introduce by adding new services and features. Do you know everything you need to about Azure? This course will teach you about the Azure App Service, monitoring and application insights, DevOps, and Team Services.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now