Security Event Logs

From: Carl Hilton (someone_at_microsoft.com)
Date: 06/10/05


Date: Fri, 10 Jun 2005 08:36:51 -0400

I have had to read some old NT4 EVT logs and noticed a lot of 528 Logons
followed in about 2-3 minutes by a 538 logoff... This appears to be fairly
consistant over several hundred pairs for most individuals...

Question:

Are there any other way for a 528 event to happen other than a CTRL-ALT-DEL
logon?

What can cause a 538 event?

Thanks
Carl



Relevant Pages

  • Re: recording users logon/off times
    ... be better off implementing your own solution, as the event logs won't cater for unexpected shutdowns, disconnections, etc. and are also sadly lacking in the exact info. you need. ... You can then build logic into reports, etc. for incidents whereby a user logs on from the same computer twice but there's no logoff event. ... You can, I am sure, tweak this so that it just reports and doesn't actually limit logons, etc. ... However the environment at work is a hybrid HP-UX/Windows environment and so that is why that situation was possible. ...
    (microsoft.public.win2000.active_directory)
  • Re: How would you log logins?
    ... Account logons do ... not have "logoff" events, and are logged on the machine that validated the ... What is the difference between Account Logons or Logon events.? ... >> Administrative Tools, Local Security Policy. ...
    (microsoft.public.win2000.security)