No announcement yet.

Server Local Logon Events

  • Filter
  • Time
  • Show
Clear All
new posts

  • Server Local Logon Events


    am trying to use Exporter Pro to extract out all the direct logons to our servers. These would be Event IDs 528 or 540 with an Event Type of 2.

    I have created an EP Config with Enabled Exports of Event Log.
    I have a WMI Class Name entry of Win32_NTLogEvent and a number of Query Properties including ComputerName, EventCode, EventType amongst many others.
    In the WMI 'Where' Clause field I currently have EventCode = 528. Purely for a test, but am recieving no results from that query on servers that I know that I have definitely logged in directly to.

    So two questions really.

    1. What might I be doing wrong so that I am getting no results.

    2. In the event that I do get results, what would I put in the WMI 'Where' Clause field to ensure that I only get EventCode's 528 or 540 and EventType 2.

    Many Thanks

  • #2
    Re: Server Local Logon Events

    OK, have managed to get some results, my formatting was a tad askew.

    However I have found that searching under EventType="2" generates more than I was anticipating and includes all direct connections from admin accounts and various agents. Is there a way of specifying in the WMI 'Where' Query to only report those results that are of Logon Process = User32?