I'm running windows server 2008 r. Last august a person with administrative authority logged into the system by Remote Desktop, and did some damage. I can see the person's computer name in the windows event log. I'm trying to determine the iP address of that person.
when I examine the log in TerminalServices-RemoteconnectionManager, i see log records that ONLY go back abnout 10 days or so. Is there a history of older log files? where do I find them?
If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.