You’ll need to enable Audit Logon Events in group policy then you can use eventcombMT to filter the required events out of the event log (available as part of the following download )’ll then have to audit the individual events (540, etc) Alternativley you may find it easier to do the following: (logon/logoff scripts)