eventvwr.msc를 통해서 로그인 한 로그들을 볼 수 있다.



로그인 유형은 다음과 같다.


Logon TypeDescription
2Interactive (logon at keyboard and screen of system)
3Network (i.e. connection to shared folder on this computer from elsewhere on network)
4Batch (i.e. scheduled task)
5Service (Service startup)
7Unlock (i.e. unnattended workstation with password protected screen saver)
8NetworkCleartext (Logon with credentials sent in the clear text. Most often indicates a logon to IIS with "basic authentication") See this article for more information.
9NewCredentials such as with RunAs or mapping a network drive with alternate credentials.  This logon type does not seem to show up in any events.  If you want to track users attempting to logon with alternate credentials see 4648.
10RemoteInteractive (Terminal Services, Remote Desktop or Remote Assistance)
11CachedInteractive (logon with cached domain credentials such as when logging on to a laptop when away from the network)


그림에서는 7번인데 화면보호기 등으로 인해서 잠금화면에서 로그인 한 시간을 보여준다.






http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4624





저작자 표시 비영리 변경 금지
신고

'Tips' 카테고리의 다른 글

윈도우 로그인 로그 (Windows7 login log)  (0) 2013.06.05
파워포인트 to EPS  (0) 2013.04.29
[워드] 옵션들  (0) 2013.04.10
Adblock filter guide  (0) 2012.11.01
Visual SVN, Tortoise SVN Branch  (0) 2012.10.31
DAV request failed log, pre-revprop-change  (1) 2012.10.29
Posted by Leo 리오 트랙백 0 : 댓글 0

티스토리 툴바