Solved

User login reporting server 2008 R2

Posted on 2014-02-12
3
255 Views
Last Modified: 2014-04-17
Hello -

I am wondering if there is a way to generate a report on the login history for a user? I found where I can see who is currently logged on (Computer management > Sessions), but is there a log somewhere of the history?

If Windows Server does not record this information, can you suggest a 3rd party tool that might?

Thanks!
Joe
0
Comment
Question by:jcaprio
  • 2
3 Comments
 
LVL 26

Expert Comment

by:pony10us
ID: 39853534
Are you wanting to check past history or going forward? Is all you want is the user and time they log in?

Something as simple as adding this to the login script would work:

rem The following line creates a rolling log file of usage by user
echo Log In %Date% %TIME% %COMPUTERNAME% >> \\servername\Logs\User\%USERNAME%.log

and if you want log off as well:

rem The following line creates a rolling log file of usage by user
echo Log Off %Date% %TIME% %COMPUTERNAME% >> \\servername\Logs\User\%USERNAME%.log

This will give you a running log of what computer and when in a file with the users name. You can reverse the %COMPUTERNAME% and %USERNAME% if you want to monitor by computer (who logs into a specific computer and when).
0
 

Author Comment

by:jcaprio
ID: 39853828
Hello -

I would like to check past history as well as going forward if possible? Is there a solution for both ways at this point?

Would you please give a detailed description on how to set up your suggestion above and also where to go to view the results?

Thank you!
0
 
LVL 26

Accepted Solution

by:
pony10us earned 500 total points
ID: 39853899
To review past history you will have to rely on the event viewer.  It depends on how much history is retained in the event viewer and then you have to search it for logon events 528 and 540 for successful logons.

As for how to implement the code above, simply add the first one to the logon script and the second one to the logoff script of your domain. It will create a file in the shared folder "\\servername\logs" (replace "servername" with the name of the server you where the share is located) named for the user with a .log extension which you can open/read with notepad since it is just a text file.

Let me know if I need to explain further.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scenario:  You do full backups to a internal hard drive in either product (SBS or Server 2008).  All goes well for a very long time.  One day, backups begin to fail with a message that the disk is full.  Your disk contains many, many more backups th…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now