I have PA Server Monitor and would like to create an Event Monitor on our Domain Controller that will monitor the security log for a specific account logon ( account is member of Domain Admins)

I have set the event monitor for Microsoft_Windows_Security_Auditing for Event ID 4672 and "usersname" then write to a text file. This text file is huge and I need to be able to limit contents.

Is there an Event ID or Logon Type I can add that will just let me know when this user logs on to any Server in our domain?

Thanks for any assistance!

asked 23 Nov '16, 14:51

techgal64's gravatar image

accept rate: 28%

Hi techgal64,

There are many different event ids that you can monitor for. Here is a link to a Microsoft page that talks about some of them and a link to our documentaion on how to filter for them. Hope this helps.

Description of security events in Windows Vista and in Windows Server 2008

How to Audit Windows Logons and Logon Failures


Please make sure to mark your questions accepted when you have your answer by clicking the gray check mark to the left of the answer.


answered 23 Nov '16, 15:05

Quinn's gravatar image

Quinn ♦♦
accept rate: 35%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported



Asked: 23 Nov '16, 14:51

Seen: 4,300 times

Last updated: 23 Nov '16, 15:05