Link to home
Start Free TrialLog in
Avatar of ITGeneral
ITGeneral

asked on

How to log ONLY Logon Type 2 events (Interactive) for eventID 4624

Using advanced logging on a 2008 R2 DC and I just want to log Interactive logon events. Logging all 4624/4634 (Logon/Logoff) events just generates waaay too much data and fills up my log file in a day. I only care about who interactively signs into the server(s). I can find all kinds of info on the 'net about how to filter security logs but I don't even want to write the other types to the file as I want to save that space for other security events.
SOLUTION
Avatar of btan
btan

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of ITGeneral
ITGeneral

ASKER

Ya I've read through most of those articles before - my problem is that the log seems to be filling up extremely quickly.  Like with just logon events being logged I might get two days worth of logging using default log sizes.  So ideally of course if I could just log interactive logons that would be my preference.  I just find it hard to believe that there's no mechanism within windows to just log interactive logons without it having to log every single interaction that any system or computer account has with the domain controller.  We're not even a big shop maybe 50 servers hundred PCs and laptops and maybe 100 users and liquor seven filling my security log in a day and a 1/2,  two days.  Even with exporting logs to file that must be near impossible to find anything that you're looking for in a large organization.
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Just to add to this - I ended up discovering that in Server 2008 R2 it seems TerminalServices sessions are logged by default in the event viewer.

In Server Manager under Windows Logs open up Applications and Services Logs -> Microsoft -> Windows -> TerminalServices-LocalSessionManager and in there you will see logon and logoff info for TS sessions to your server.
thanks for sharing