I need help to create a query on ITS.
We have some terminal server, on Intrust we logged this events:
- Windows-TerminalServices LocalSessionManager/Operational Log
- Windows Security log
We need to track LOGIN and LOGOFF events for single users.
If I search the events "eventid="4624" I get to many LOGONs events (same time) for one user.
I need the single event.
Thanks for help me