I have a question about monitoring the logon's on a terminal server. Our clients want to know which user log on from what computer (or IP).
so i could monitor for event 552 in the security log on the terminal server, so far no problem.
From there i would need to extract: DATE / TIME / <<DOMAIN\USERNAME>> / <<COMPUTERNAME>> / <<SOURCE IP>> and add that to a log/text file on the terminal server.
suggestions are very welcome !