User Logout event RRS feed

  • Question

  • We would like to now how to find when user logs off by monitoring Windows event log on AD domain controller. We can see the following events:

    - 4768 A Kerberos authentication ticket (TGT) was requested

    - 4769 A Kerberos service ticket was requested

    - 4624 An account was successfully logged on

    - 4634 An account was logged off

    The user initiated logoff message 4647 can be found only on the workstation that logged off, we can't find it on AD domain controller. Is there any way to know about the logoff without querying the workstations?

    Sunday, May 23, 2010 12:29 PM


All replies