Since I have set security auditing on our W2K server, the information that accumulates there (viewed by the MS event viewer) is very overwhelming at best. Is there a better way to look at log on events, or does one use a 3rd party software? Thanks--Richard