Solved

I need help with XML code for Logon and logoff events in Server 2008 within a specific time frame of the last 2 days

Posted on 2015-02-06
4
97 Views
Last Modified: 2015-02-10
I have the first part of the XML code for the Logon for a user for the last 2 days as follows:
<QueryList>
  <Query Id="0" Path="Security">
    <Select Path="Security">
    *[System[(EventID=4624)
    and
    TimeCreated[timediff(@SystemTime) &lt;= 172800000]]
    and
    EventData[Data[@Name='TargetUserName'] and (Data='USERNAME')]
    and
    EventData[Data[@Name='LogonType'] and (Data='10')]]
    </Select>
  </Query>
</QueryList>

But have not been able to create the XML code to add to obtain the logoff for the user. Any help would be appreciated
0
Comment
Question by:mopalinski
  • 2
  • 2
4 Comments
 
LVL 39

Expert Comment

by:footech
ID: 40595509
So, this appears to be an XPath form for a custom filter of event data.  I believe all you need is the modification as shown below.
<QueryList>
  <Query Id="0" Path="Security">
    <Select Path="Security">
    *[System[(EventID=4624 or EventID=4647)
    and
    TimeCreated[timediff(@SystemTime) &lt;= 172800000]]
    and
    EventData[Data[@Name='TargetUserName'] and (Data='USERNAME')]
    and
    EventData[Data[@Name='LogonType'] and (Data='10')]]
    </Select>
  </Query>
</QueryList>

Open in new window

0
 

Author Comment

by:mopalinski
ID: 40598276
Sorry, but it still only shows Logon and not logoff with your suggestion.
0
 
LVL 39

Accepted Solution

by:
footech earned 500 total points
ID: 40598710
Try 4634 instead of 4647.
0
 

Author Closing Comment

by:mopalinski
ID: 40600614
Worked like a charm. Thank you so much.
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Why is a PSO not being set for users 2 27
Windows 2003 Split DNS solution ? 3 50
Best method to remove 360 Safety Guard from Windows 8 4 395
how to count files? 4 30
Many times while working on a computer regardless of any Operating System, lag and crashes seem to creep in, hindering your working speed. Sometimes, it can also cause your work to be lost unexpectedly and as a result, you are unable to meet your de…
When you upgrade from Windows 8 to 8.1 or to Windows 10 or if you are like me you are on the Insider Program you may find yourself with many 450MB recovery partitions.  With a traditional disk that may not be a problem but with relatively smaller SS…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question