Event Details
User Activity->Logons->Successful Logons->Windows 2008->EventID 4626 - User / Device claims information.
EventID 4626 - User / Device claims information.
 Sample:
Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          10/16/2016 4:12:03 PM
Event ID:      4626
Task Category: User / Device Claims
Level:         Information
Keywords:      Audit Success
User:          N/A
Computer:      DC01.contoso.local
Description:
User / Device claims information

Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Logon Type:   			3

New Logon:
	Security ID:		CONTOSO\dadmin
	Account Name:		dadmin
	Account Domain:		CONTOSO
	Logon ID:		0x136F7B
	Event in sequence:	1 of 1

User Claims:			ad://ext/cn:88d2b96fdb2b4c49 <%%1818> : "dadmin"
				ad://ext/Department:88d16a8edaa8c66b <%%1818> : "IT"
                        
Device Claims:			-
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows Vista (2008)
Windows 7 (2008 R2)
Windows 8 (2012)
Windows 8.1 (2012 R2)
Windows 10 (2016)
Category Logon/Logoff
Source Microsoft-Windows-Security-Auditing
TaskCategory User / Device Claims
EventId 4626
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. DateTime 10.10.2000 19:00:00
Who Account or user name under which the activity occured. New Logon: Account Name dadmin
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "Logon" Logon
Where The name of the workstation/server where the activity was logged. Computer DC1
Where From The name of the workstation/server where the activity was initiated from. - 10.10.10.10
Severity Specify the seriousness of the event. "Medium" Medium
WhoDomain New Logon: Account Domain CONTOSO
WhereDomain -
Result Successful or Failed. "Successful" Successful
Failure Reason "Successful" Successful
Whom InsertionString6 dadmin
Comments
You must be logged in to comment