I understand how group policy works and I have turned on auditing for user logon events but its capturing way more information then I initially wanted.
My manager wants to capture logon/logoff events to ensure when certain people are saying they are at work logged on and working they really are.
Is there anyway to narrow this info down. Also I had my co-worker log off and log back on and it didn’t seem to capture it. Did I not turn on the right auditing function on the domain controller?
Any help is appreciated. Thanks.