Discovering logon events in the Event Log
Each time you attempt to log on to Windows, whether you are successful or not, Windows logs the attempt in the Security log. These log events can help determine who logged into a computer and when.
Windows defines several different logon types. A logon type of 2 indicates a local console login (logging on to a physical host), while a logon type of 10 indicates logon over RDP. Other logon types include service logon (type 5), batch or scheduled task (type 4), and console unlock (type 7).
You can read more detail in this article: https://docs.microsoft.com/previous-versions/windows/it-pro/windows-server-2003/cc787567(v=ws.10). Note that this document is somewhat outdated, and Microsoft has not updated it for later versions of Windows. With that said, the information continues to be correct.
In this recipe, you use PowerShell to examine the Security event log and look at the logon events.
Getting ready
You run this recipe on DC1
, a domain controller...