User Logon

From: Austin Henderson (austin_at_NOSPAM.firstfleetinc.com)
Date: 09/23/03


Date: Tue, 23 Sep 2003 08:55:42 -0500


I have a mixed mode domain and I need to determine if any user tried to
logon from a certain computer at any point in a two day period. THe event
viewer appears to be very cryptic and since I have three controllers there
are 3x the entries... how can I easily determine this?

Can it be done?

Thank you



Relevant Pages

  • Re: Security Log Help
    ... solution and verify that your domain controllers have the correct IP ... > Type: Failure ... An unexpected error occurred during logon ...
    (microsoft.public.win2000.security)
  • Re: Many Logon/Logoff Entries
    ... last week-end troubleshooting a Logon/LogOff issue and discovered just how ... over 170,000 of these entries in the Security Log. ... > Logon ID: ... > Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: obscure logon events?
    ... These don't explain reason of these event entries. ... Logon even: 540 A user successfully logged on to a network. ... You can safely ignore this event log and it should ...
    (microsoft.public.windows.server.sbs)
  • Re: Restrict logon access to specific PCs
    ... > Allow logon locally - your user group. ... you want to define the settings but have no entries. ... >> RZE SA ...
    (microsoft.public.windows.server.active_directory)
  • Security event crazyness... help!
    ... 540/538 as teh even type here is even log entries, ... Event Category: Logon/Logoff ... Successful Network Logon: ... Caller User Name: - ...
    (microsoft.public.windows.server.general)