I set the group policy to audit logon events and account logon events, success and failure.
I also added the "everyone" group to auditing under the RDP properties (in terminal server configuration), permissions, advanced, auditing tab, and selected everything there is to audit...
Hi,
I think somebody snatched my admin username and password. In order to catch this guy I need log files to prove my theory.
I need to log account logon's which I am already doing. Problem is that it logs username as "admin" and workstation as "my terminal server" or the...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.