Search Windows security log

Asset 23

How to search the Windows Event Log for logins by username

Posted on 10 September 2012 by Beaming Support

In order to search the Windows Event Log for logins by username you will need to be using Windows Server

The following steps will allow you to search the Windows Event log for logins by username.

1. Open event viewer and select the Security Logs

2. Select filter current log in the Actions pane.

3. Select XML tab

4. Select ‘Edit query manually’

5. Replace the contents with

<QueryList>
<Query Id=”0″>
<Select Path=”Security”>
*[EventData[Data[@Name=’SubjectUserName’] and (Data=’USERNAME’)]]
</Select>
</Query>
</QueryList>

6. Change the USERNAME field to the appropriate username configured in active directory for the user you are searching security events for.

7. The results now show your custom security log XML search.

8. Do not forget to clear filter to revert back to unfiltered view.

Avoid internet downtime

Subscribe and we’ll send a monthly email update with guidance to keep your business productive and secure online.

  • This field is for validation purposes and should be left unchanged.

Latest tech support posts – shared monthly!

Get all the latest tech support answers drop straight in your inbox. Sign up to our email round up. Add your email address below

  • This field is for validation purposes and should be left unchanged.