Thursday, October 6, 2016
How to track users logon logoff using a script
How to track users logon logoff using a script
How to track users logon/logoff
The Auditing
Option 1:
1. Enable Auditing on the domain level by using Group Policy:
Computer Configuration / Windows Settings/ Security Settings/Local Policies / Audit Policy
There are two types of auditing that address logging on,they are Audit Logon Events and
Audit Account Logon Events.
Audit logon events records logons on the PC(s) targeted by the policy and the results appear in the Security Log on that PC(s).
Audit Account LogonEvents tracks logons to the domain,and the results appear in the Security Log on domain controllers only.
2. Crete a logon script on the required domain/OU/user account with the following content:
echo %date% , %time%, %computername%, %username% , %sessionname%, %logonserver% > >
SERVERSHARENAME$LOGON.LOG
3. Crete a logoff script on the required domain/OU/user account with the following content:
echo %date% , %time%, %computername%, %username% , %sessionname%, %logonserver% > >
SERVERSHARENAME$LOGOFF.LOG
NOTE : Please be aware that unauthorized users can change the scripts,due to the requirement that
the SHARENAME$ will be writeable by users.
Option 2:
Use WMI/ ADSI to query each domain controller for logon/logoff events.
Go to link Download
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment