Make sure you auditing is enabled on your security logs.
Look for event id 538.
---
Event ID 538 can be generated under one of the following conditions [1]:
Event ID 538 Possibilities Logon Type
Network Logoff 3
Net use disconnection 3
Auto-disconnect 3
Interactive Logoff 2
---
http://www.microsoft.com/technet/pro.../logonoff.mspx




Reply With Quote