I want to audit when a user first logs onto their system for the day and when they log of for the day. I have looked through my Active Directory Security logs and notice users with multiple success logs within seconds of each other then a log off within a minute. Event ID's of 540 and 538. How can I narrow this down?
Thanks.
