Hi,
I think somebody snatched my admin username and password. In order to catch this guy I need log files to prove my theory.
I need to log account logon's which I am already doing. Problem is that it logs username as "admin" and workstation as "my terminal server" or the server running terminal services in remote administration mode. I need to trace it to the client machine name or ip address from which the person connected to the server using terminal server client. I see winsta.exe shows you the connection and also "connected from". This is typically what I need, but I need the server and all the servers in my domain to log this. Winsta.exe is very limited for this reason. It cannot log and you need to run it on every server.
Is there some way to get this info into a logfile or event viewer?
Any help please!
Stef
I think somebody snatched my admin username and password. In order to catch this guy I need log files to prove my theory.
I need to log account logon's which I am already doing. Problem is that it logs username as "admin" and workstation as "my terminal server" or the server running terminal services in remote administration mode. I need to trace it to the client machine name or ip address from which the person connected to the server using terminal server client. I see winsta.exe shows you the connection and also "connected from". This is typically what I need, but I need the server and all the servers in my domain to log this. Winsta.exe is very limited for this reason. It cannot log and you need to run it on every server.
Is there some way to get this info into a logfile or event viewer?
Any help please!
Stef