Here is are a couple small scripts that can be deployed through GPO that will log the time, computer name, and user name of domain computer logon events.

Essentially there are two scripts, one that is run at logon and the other is run at log off. The logon script is as follows:

@ECHO OFF
echo %date%,%time%,logon,%username% » “\server\LoginTracking\logs\computers\computer-%computername%.txt”
echo %date%,%time%,logon,%computername% » “\server\LoginTracking\logs\users\user-%username%.txt”

The script will write the date, time, event type (logon/logoff), and computer or username to a log. The script actually write two seperate logs, one by computer name and the other by username. That way you can see what computers a user has been logging into and what users have been logging into a specific computer.

The logoff script is identical except for the event type.

@ECHO OFF
echo %date%,%time%,logoff,%username% » “\server\LoginTracking\logs\computers\computer-%computername%.txt”
echo %date%,%time%,logoff,%computername% » “\server\LoginTracking\logs\users\user-%username%.txt”