How to write an Xpath Query for the Event Viewer in the new versions of Windows?

So today I finally decided to take a look at the event logs on my
computer. My roommate used my desktop somehow and I am trying to uncover how he
did it. After looking through the security logs I found that there was a remote
desktop connection from another computer I left unlocked during the time he
used it so I guess that explains the situation. After that I was curious to
find out if he accessed any other computer so I was trying to look at other
logs. It is a pain to go through the entire security log so I was looking for a
way to filter the results. Is there a way to filter all those and only display
the logon and logoff attempts via Terminal Services?

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.