G
Guest
I have been going through our DC security logs trying to find out what
workstation a user logged into. I am able to find the event showing the user
account which has a Login ID and GUID but I have been unable to determaine
the workstation he was logged into. Is there a way to do this?
Thanks in advancce for your help
Sample Event Below
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 11/8/2005
Time: 9:04:40 AM
User: MYDOMAIN\bsmith
Computer: MYDC1
Description:
Successful Network Logon:
User Name: bsmith
Domain: MYDOMAIN
Logon ID: (0x1,0xAD5A23423)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {3e21321317-2abe-7133-67e1-d73132342b4d}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
workstation a user logged into. I am able to find the event showing the user
account which has a Login ID and GUID but I have been unable to determaine
the workstation he was logged into. Is there a way to do this?
Thanks in advancce for your help
Sample Event Below
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 11/8/2005
Time: 9:04:40 AM
User: MYDOMAIN\bsmith
Computer: MYDC1
Description:
Successful Network Logon:
User Name: bsmith
Domain: MYDOMAIN
Logon ID: (0x1,0xAD5A23423)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {3e21321317-2abe-7133-67e1-d73132342b4d}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.