all log on and log off events are tracked (if you configure GPO or local security policy to track logon events) in the Event Viewer Security Log. To enable auditing of these events either configure a Domain GPO or a local security policy (by running gpedit.msc from the Run line). Go to comptuer configuration -> Windows Settings - > Security Settings -> Local Policies -> Audit Policies.