Does anyone know if there is a way to capture a user logoff event?
We want to be able to audit the length of time a user is logged into a system.
Thanks
By default, UDT supports Kerberos authentication scheme only.
Authentication |
Operating System |
Event Code |
Kerberos |
Windows 2003 |
672 and 673 |
NTLM |
Windows 2003 |
680 |
Kerberos |
Windows 2008 and later |
4768 and 4769 |
NTLM |
Windows 2008 |
4776 |
I don't think it logs the log off.
It would be a great Feature Request though.
SolarWinds solutions are rooted in our deep connection to our user base in the THWACK® online community. More than 195,000 members are here to solve problems, share technology and best practices, and directly contribute to our product development process.