This report provides a list of network connections to other
computers. The report includes the following events from the
Security event log with the Kerberos or
NtLmSsplogon process:
540—Successful Logon
540—Successful Logoff
The report is sorted by user account name and logon event, with
the most recent logon event listed first. The columns of this
report are defined as follows:
User Account
Specifies the name of the user account that requested the
connection.
Logon
Specifies the date and time the user account identified in the
User Account column requested the connection.
Logoff
Specifies the date and time the user account identified in the
User Account column ended the connection. If this column is
blank, the user did not end the connection within the date and time
range specified in the report criteria. For a logon and logoff to
be paired, the logon ID (session) must be identical.
Elapsed Time
Specifies the difference between the logon and logoff times in
the Logon and Logoff columns.
Logged On
Specifies the name of the system connecting to a network
share.
Connected To
Specifies the name of the system to which the connection was
made.