Enable Successful User Logon

The following article explains how to enable successful user logon/logoff through event viewer security logs.

When the Successful Logon/Logoff Report from Security Event viewer logs is run, if the service account has local admin rights instead of domain admin rights, please follow the steps below:

  • Step 1: Create a folder called AuditLgnLgf in the root installation

A screenshot of a computer

Description automatically generated
  • (Optional) To skip Netlogon events, create an ExcludeNetLgnEvents folder under the AuditLgnLgf folder in the installation folder

A screenshot of a computer

Description automatically generated

  • Step 2: Un-install and re-install the AD Auditing Agent by clicking on Upgrade agent

A screenshot of a computer

  • Step 3: Un-check the option Audit Successful User Logon/Logoff

A screenshot of a computer

Description automatically generated

  • Step 4: Re-start the Lepide service by right-clicking on Component Management

A screenshot of a computer

Description automatically generated

  • If the AD auditing is without agent, please perform the steps 1, 3 and 4 above

  • After some time, it will start populating the successful User Logon/Logoff

  • You can verify this by checking the security logs of DCs under Event ID: 4624