Discovering logon events in the event log
Each time you attempt to log on, whether you are successful or not, Windows logs the attempt. These log events can help you determine who logged on to a computer and when.
In Windows, there are several different logon types. A logon type of 2 indicates a local console logon (that is, logging on to a physical host), while a logon type of 10 indicates logon over RDP. Other logon types include service logon (type 5), batch or scheduled task (type 4), and console unlock (type 7).
You can read more details in this article: https://docs.microsoft.com/previous-versions/windows/it-pro/windows-server-2003/cc787567(v=ws.10). Note that this document is somewhat outdated and Microsoft has not updated it for later versions of Windows, although the information continues to be correct.
In this recipe, you use PowerShell to examine the Security event log and look at the logon events.
Getting ready
You run this recipe on DC1
, a domain...