Solved

extract logon/logoff from Windows 2008 event logs

Posted on 2011-03-18
5
1,289 Views
Last Modified: 2012-05-11
Hello,

Windows Server 2008 64-bit.

I'm looking for a way to parse logon/logoff activity for a specific user from the logon server's evtx files. I've checked out several snipets of batch and VBS files but have not been able to get them to work with evtx files.

Thanks,

Geoff
0
Comment
Question by:geoffdavis
  • 2
5 Comments
 
LVL 6

Accepted Solution

by:
Raneesh Chitootharayil earned 250 total points
ID: 35170209
0
 
LVL 8

Assisted Solution

by:Volox
Volox earned 250 total points
ID: 35172523
There is the LogParser that MS makes available...
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=890cd06b-abf8-4c25-91b2-f8d975cf8c07&displaylang=en

It not only will parse logs and let you search through them, it will allow you to do it for multiple source machines at the same time - so if you have multiple domain controllers, you can search the logs of all of them to find the entry you are looking for.

Check out the pre-built queries that are included (or at least they used to be included) that will help get you started.
0
 
LVL 8

Expert Comment

by:Volox
ID: 35732985
I think that raneeshcr gave a link to a valid thread and without feedback I have no reason to believe that my answer did not provide a viable solution.  I suggest a split of points between the two of us that responded to this questino.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Computer science students often experience many of the same frustrations when going through their engineering courses. This article presents seven tips I found useful when completing a bachelors and masters degree in computing which I believe may he…
Find out what you should include to make the best professional email signature for your organization.
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question