Event Details
Operating System->InTrust Superior logon/logoff events->EventID 103 - User session was ended by computer lock.
A user session was ended on computer %Where% by user %IS1% locking the computer at %IS15%. The user session lasted %IS16%.

Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: InTrust User Session Tracking
Filtering Field Equals to Value
EventId 103
Field Matching
FieldDescriptionStored inSample Value
DateTime Date/Time of event origination in GMT format. -
Source Name of an Application or System Service originating the event. -
Type Warning, Information, Error, Success, Failure, etc. -
User Domain\Account name of user/service/computer initiating event. -
Computer Name of server workstation where event was logged. -
EventID Numerical ID of event. Unique within one Event Source. -
Description The entire unparsed event message. -
Log Name The name of the event log (e.g. Application, Security, System, etc.) -
User Name User name. -
Domain Name Domain name. -
DNS Domain Name DNS domain name. InsertionString3
User's SID User's SID. InsertionString4
LUID - Session Logon LUID - session logon. InsertionString5
Terminal Services Session ID Terminal Services session ID. InsertionString6
Logon Type Logon type. InsertionString9
Source Workstation Source display name. InsertionString10
Source Network Address Source network address. InsertionString11
Start Time Start time (yyyy-MM-dd HH:mm:ss). InsertionString13
End Time End time (yyyy-MM-dd HH:mm:ss). InsertionString15
Duration Duration (HH:mm:ss). InsertionString16
