In a Windows domain, all logs from our domain controllers are being sent to the SEM. We are wanting to know the IP address for the device where a user is logging in from yet can't seem to find a consistent record of it through the logs. Is that a field that is commonly recorded or do I need to turn on additional auditing for the domain controllers? For example, for user "JohnDoe", i'd like to know that he logged in from machine xyz.xyz.xyz.100 on Monday, and on Thursday he logged in from xyz.xyz.xyz.200. In the SEM, I chose Historical Events, set a date range and then filtered by username = "JohnDoe". Lots of events to go through, but not seeing consistent information on where this individual is logging in from so maybe I'm not doing it right?