I have found below log on my domain controller, 1/9/2010,7:57:29 AM,Security,Success Audit,Logon/Logoff ,540,TMN\USERNAME,DC,"Successful Network Logon: User Name: USERNAME Domain: TMN Logon ID: (0x0,0xE55832A) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {3362e1d8-b952-9b84-8911-df846e16c05e} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 172.18.10.xxx Source Port: 0 From Information above and related articles on internet, i conclude that either of following, i) User logged into this server Or i) User accessed some share on this server though its authentication event triggered on domain controller where I have found this log. Correct me if I am wrong.