Event Details
User Activity->Logons->Successful Logons->Windows 2000-2003->EventID 540 - Successful Network Logon [Win 2003]
EventID 540 - Successful Network Logon [Win 2003]
 Sample:
Event Type:     SuccessAudit
Event Source:   Security
Event Category: Logon/Logoff
Event ID:       540
Date:           10/26/2009 12:00:00 AM
Time:           07:31:44
User:           NT AUTHORITY\SYSTEM
Computer:       DC1
Description:    
Successful Network Logon:

	User Name:	DC1$

	Domain:		RESEARCH

	Logon ID:		(0x0,0x60F7C2)

	Logon Type:	3

	Logon Process:	Kerberos

	Authentication Package:	Kerberos

	Workstation Name:	

	Logon GUID:	{1be8f5d6-8f8a-62c1-d74c-5d4a7950138a}

	Caller User Name:	-

	Caller Domain:	-

	Caller Logon ID:	-

	Caller Process ID: -

	Transited Services: -

	Source Network Address:	127.0.0.1

	Source Port:	0
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows 2003
Source Security
Category Logon/Logoff
EventId 540
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. DateTime 12/14/2009 6:59:09 AM
Who Account or user name under which the activity occured. User Name DC1$
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "Logon" Logon
Where The name of the workstation/server where the activity was logged. Computer DC1
Where From The name of the workstation/server where the activity was initiated from. Workstation Name
Severity Specify the seriousness of the event. "Medium" Medium
WhoDomain Domain RESEARCH
WhereDomain -
Result Successful or Failed. "Successful" Successful
Failure Reason "Successful" Successful
Comments
You must be logged in to comment