Make sure you auditing is enabled on your security logs.

Look for event id 538.

---
Event ID 538 can be generated under one of the following conditions [1]:

Event ID 538 Possibilities Logon Type
Network Logoff 3
Net use disconnection 3
Auto-disconnect 3
Interactive Logoff 2
---

http://www.microsoft.com/technet/pro.../logonoff.mspx