I'm running windows server 2008 r. Last august a person with administrative authority logged into the system by Remote Desktop, and did some damage. I can see the person's computer name in the windows event log. I'm trying to determine the iP address of that person.
when I examine the log in TerminalServices-RemoteconnectionManager, i see log records that ONLY go back abnout 10 days or so. Is there a history of older log files? where do I find them?