I am reviewing the audit log on one of my '08 servers and am simply amazed at the massive number of events orruring. Using the logonID, I am able to match loon and logoff events on a single machine loging on and off several time each minute. Multiply that by 30 or so machines on this network, and the Audit Event log is will over 300K records. Is this normal or is this poining to a network issue? BTW, the server in question is an AD controller, with file sharing, and running Exchange 2007.