The following article explains how to enable successful user logon/logoff through event viewer security logs.
When the Successful Logon/Logoff Report from Security Event viewer logs is run, if the service account has local admin rights instead of domain admin rights, please follow the steps below:
Step 1: Create a folder called AuditLgnLgf in the root installation
(Optional) To skip Netlogon events, create an ExcludeNetLgnEvents folder under the AuditLgnLgf folder in the installation folder
Step 2: Un-install and re-install the AD Auditing Agent by clicking on Upgrade agent
Step 3: Un-check the option Audit Successful User Logon/Logoff
Step 4: Re-start the Lepide service by right-clicking on Component Management
If the AD auditing is without agent, please perform the steps 1, 3 and 4 above
After some time, it will start populating the successful User Logon/Logoff
You can verify this by checking the security logs of DCs under Event ID: 4624