We are running Languard SELM v4(Security Event Log Monitor) to gather domain controller security evt logs and compile the events into a database. My boss wants to be able to determine the time users log onto the domain as well as when they log off. The problem is that this data that is being gathered is not really telling me anything because apparently logon events (mostly 528, but sometimes 540 also) are added to the log when someone maps a drive, or is authenticated in a way other than logging onto the domain. Have the same problem with logoffs (538). I don't care about when someone maps a drive or opens their email and authenticates to the exchange server, all I want to know is domain logon/logoff times. How can I get this? We have all W2K Prof workstations, but an NT4 domain with all NT4 DCs. Will be going to Active Directory in the next year. Is there any built-in functionality in AD that serves this purpose? How can I do it before we go to AD?