Hi!
It's unreal to install Splunk forwarder to all Windows PCs - there are a lot of users. I think that the easiest way is to collect this log from all PCs in one place and upload it to Splunk.
It doesn't matter of logon types. I will to try on interactive logon.
We have Win 2000-2003-XP-7-8-2008 "Full house" 🙂
... View more