0HWD)UDPH$GPLQLVWUDWRUªV*XLGH
$8',7/2**HQHUDWH/RJRQ/RJRII5HSRUWV
'HVFULSWLRQ
The auditlog utility generates reports of logon/logoff activity for a MetaFrame
server based on the Windows NT Server security Event Log. To use auditlog,
logon/logoff accounting must be enabled. Report output can be redirected to a file.
6\QWD[
auditlog [username | session] [/eventlog:filename]
[/before:mm/dd/yy] [/after:mm/dd/yy]
[[/write:filename] | [/detail | /time] [/all]]
auditlog [username | session] [/eventlog:filename]
[/before:mm/dd/yy] [/after:mm/dd/yy]
[[/write:filename] | [/detail] | [/fail | /all]]
auditlog [/clear:filename]
auditlog [/?]
3DUDPHWHUV
username
Specifies a username for which to produce a logon/logoff report. Use this to
examine the logon/logoff record for a particular user.
session
Specifies the name of a session for which to generate a logon/logoff report.
Use this to examine the logon/logoff record for a particular session.
2SWLRQV
/eventlog:filename
Specifies the name of a backup security Event Log to use as input to auditlog.
You can create a backup security log from the Event Log Viewer or by using
auditlog /clear:filename.
/before:mm/dd/yy
Reports on logon/logoff activity only before mm/dd/yy.
/after:mm/dd/yy
Reports on logon/logoff activity only after mm/dd/yy.