Note: This article was originally published in 2008. Some steps, commands, or software versions may have changed. Check the current General documentation for the latest information.
So today I finally decided to take a look at the event logs on my computer. My roommate used my desktop somehow and I am trying to uncover how he did it. After looking through the security logs I found that there was a remote desktop connection from another computer I left unlocked during the time he used it so I guess that explains the situation. After that I was curious to find out if he accessed any other computer so I was trying to look at other logs. It is a pain to go through the entire security log so I was looking for a way to filter the results. Is there a way to filter all those and only display the logon and logoff attempts via Terminal Services?
Summary
You’ve successfully learned write an xpath query for the event viewer in the new versions of windows?. If you run into any issues, double-check the prerequisites and ensure your General environment is properly configured.