Hi all,

I have a question about monitoring the logon's on a terminal server. Our clients want to know which user log on from what computer (or IP).

so i could monitor for event 552 in the security log on the terminal server, so far no problem.

From there i would need to extract:  DATE / TIME / <<DOMAIN\USERNAME>> / <<COMPUTERNAME>> / <<SOURCE IP>>  and add that to a log/text file on the terminal server.

suggestions are very welcome !