I'm sorry, but you need to supply a little bit more info before anyone can help you with specific searches.
1) First, you need to look at your log data to determine which event signifies a login.
2) Then you have to verify that the timestamps are correct, i.e. showing correct time in an acceptable format.
3) Verify that user actions are logged properly, e.g. events should at least contain UserID, Operation, Object being operated upon, Success/Fail status.
4) Get logs into Splunk.
5) Create searches and reports for auditing system use.
When you've done 1-4, you can get help with 5.
/k
... View more