Solved

Monitor user logins

Posted on 2010-11-11
7
431 Views
Last Modified: 2012-05-10
I am looking for the easiest way to just view user login authentication on our network.
0
Comment
Question by:drgleockler
7 Comments
 
LVL 13

Expert Comment

by:BCipollone
ID: 34115808
You should be able to view this through eventvwr
0
 

Author Comment

by:drgleockler
ID: 34115823
I can see a PC name but not the user account in the security log. Is there a certain event id to look for?
0
 
LVL 5

Expert Comment

by:TheMetalicOne
ID: 34115839
Agreed, by default all your users authentication requests are logged on the domain controller in the security log.  When reviewing the log you can easily filter it out to follow a specific user if you wish.
0
 
LVL 5

Accepted Solution

by:
TheMetalicOne earned 500 total points
ID: 34115852
Look for the category Logon/Logoff or event ID 540

You can also right click on the security log and go to properties, click on the filter tab and then you can enter in the username if you wish.
0
 
LVL 16

Expert Comment

by:ThinkPaper
ID: 34115868
Not sure if this is what you're looking for, but I posted a related question a while back regarding an easy way to keep track of users and what machines they logged on to. If you're up to the task (requires some vbscript and access to the AD "Description" field, it might be one way to go about it...

http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_24773750.html
0
 
LVL 7

Expert Comment

by:BobintheNoc
ID: 34116220
If you're actively auditing the Logon Events, you'll capture the usernames.  Sometimes though, sorting through those security logs on the dc can be time consuming.  Keep in mind too, that each DC maintains it's own logs.

A nice MS utility, EVENT COMB tool will help alot, worth checking out.  Sure, it can take a while to sort through the multiple DCs, but at least it's a single interface.
http://support.microsoft.com/kb/308471
0
 

Author Comment

by:drgleockler
ID: 34136785
Is the logon event id different for Windows Server 2008 R2?
0

Join & Write a Comment

As network administrators; we know how hard it is to track user’s login/logout using security event log (BTW it is harder now in windows 2008 because user name is always “N/A” in the grid), and most of us either get 3rd party tools, or just make our…
[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now