Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

I need help with XML code for Logon and logoff events in Server 2008 within a specific time frame of the last 2 days

Posted on 2015-02-06
4
Medium Priority
?
104 Views
Last Modified: 2015-02-10
I have the first part of the XML code for the Logon for a user for the last 2 days as follows:
<QueryList>
  <Query Id="0" Path="Security">
    <Select Path="Security">
    *[System[(EventID=4624)
    and
    TimeCreated[timediff(@SystemTime) &lt;= 172800000]]
    and
    EventData[Data[@Name='TargetUserName'] and (Data='USERNAME')]
    and
    EventData[Data[@Name='LogonType'] and (Data='10')]]
    </Select>
  </Query>
</QueryList>

But have not been able to create the XML code to add to obtain the logoff for the user. Any help would be appreciated
0
Comment
Question by:Michael Opalinski
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 41

Expert Comment

by:footech
ID: 40595509
So, this appears to be an XPath form for a custom filter of event data.  I believe all you need is the modification as shown below.
<QueryList>
  <Query Id="0" Path="Security">
    <Select Path="Security">
    *[System[(EventID=4624 or EventID=4647)
    and
    TimeCreated[timediff(@SystemTime) &lt;= 172800000]]
    and
    EventData[Data[@Name='TargetUserName'] and (Data='USERNAME')]
    and
    EventData[Data[@Name='LogonType'] and (Data='10')]]
    </Select>
  </Query>
</QueryList>

Open in new window

0
 

Author Comment

by:Michael Opalinski
ID: 40598276
Sorry, but it still only shows Logon and not logoff with your suggestion.
0
 
LVL 41

Accepted Solution

by:
footech earned 2000 total points
ID: 40598710
Try 4634 instead of 4647.
0
 

Author Closing Comment

by:Michael Opalinski
ID: 40600614
Worked like a charm. Thank you so much.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

My purpose is to describe the basic concepts of virtual memory as implemented in a modern Windows-based operating system. I will also describe the problems inherent in older systems and how virtual memory solves them. The dark ages - before virtu…
INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question