Submit a ticketCall us

Welcome to the NEW Success Center. Search all resources (documentation, videos, training, knowledge base articles) or browse resources by product. If you are unable to find what you are looking for, please contact us at customersuccess@solarwinds.com

 

 

 

 

Home > Success Center > Log & Event Manager (LEM) > Unable to log Windows Interactive Logon events

Unable to log Windows Interactive Logon events

Created by Jason Dee, last modified by MindTouch on Jun 23, 2016

Views: 994 Votes: 2 Revisions: 5

Overview

This article provides brief information and steps to resolve the issue when you are unable to find any interactive Logon events for your Windows host. 

UserLogon events in nDepth and other type of events are visible, except interactive Logon. 

 

 

Environment

All LEM versions

 

Cause 

The issue is caused when account events are logged on to the domain controller, but actual logon events are logged on  to the local machines.

 

Resolution

In order to log Interactive Logon events from your workstations, you must meet the following conditions:

  • The LEM Agent is installed on the workstations you want to monitor, not just the domain controller(s).
  • The group policy applied to your workstations (most likely the Default Domain Policy) is configured to monitor user logon events.

 

If the above conditions are true, you should be able to locate Interactive Logon events in nDepth by searching for the following conditions:

 

UserLogon.LogonType = Windows: Interactive

 

OR

 

User.LogonType = Windows: Remote Interactive Logon

 

For additional information, see Audit logon events from the Microsoft website. 

 

 

Last modified
20:24, 22 Jun 2016

Tags

Classifications

Public