Solved

I need help with XML code for Logon and logoff events in Server 2008 within a specific time frame of the last 2 days

Posted on 2015-02-06
4
98 Views
Last Modified: 2015-02-10
I have the first part of the XML code for the Logon for a user for the last 2 days as follows:
<QueryList>
  <Query Id="0" Path="Security">
    <Select Path="Security">
    *[System[(EventID=4624)
    and
    TimeCreated[timediff(@SystemTime) &lt;= 172800000]]
    and
    EventData[Data[@Name='TargetUserName'] and (Data='USERNAME')]
    and
    EventData[Data[@Name='LogonType'] and (Data='10')]]
    </Select>
  </Query>
</QueryList>

But have not been able to create the XML code to add to obtain the logoff for the user. Any help would be appreciated
0
Comment
Question by:mopalinski
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 40

Expert Comment

by:footech
ID: 40595509
So, this appears to be an XPath form for a custom filter of event data.  I believe all you need is the modification as shown below.
<QueryList>
  <Query Id="0" Path="Security">
    <Select Path="Security">
    *[System[(EventID=4624 or EventID=4647)
    and
    TimeCreated[timediff(@SystemTime) &lt;= 172800000]]
    and
    EventData[Data[@Name='TargetUserName'] and (Data='USERNAME')]
    and
    EventData[Data[@Name='LogonType'] and (Data='10')]]
    </Select>
  </Query>
</QueryList>

Open in new window

0
 

Author Comment

by:mopalinski
ID: 40598276
Sorry, but it still only shows Logon and not logoff with your suggestion.
0
 
LVL 40

Accepted Solution

by:
footech earned 500 total points
ID: 40598710
Try 4634 instead of 4647.
0
 

Author Closing Comment

by:mopalinski
ID: 40600614
Worked like a charm. Thank you so much.
0

Featured Post

Guide to Performance: Optimization & Monitoring

Nowadays, monitoring is a mixture of tools, systems, and codes—making it a very complex process. And with this complexity, comes variables for failure. Get DZone’s new Guide to Performance to learn how to proactively find these variables and solve them before a disruption occurs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Lodctr fails with code 5 - Access denied 2 864
Microsoft software rollup and service pack check website 7 48
Why frequent account locked out - Event ID 4740 6 168
CBS.LOG 2 183
Preface Having the need * to contact many different companies with different infrastructures * do remote maintenance in their network required us to implement a more flexible routing solution. As RAS, PPTP, L2TP and VPN Client connections are no…
Many times while working on a computer regardless of any Operating System, lag and crashes seem to creep in, hindering your working speed. Sometimes, it can also cause your work to be lost unexpectedly and as a result, you are unable to meet your de…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question