Howdy,
Does anyone know if UDT can use the logon/logoff audits from the Advanced Audit Policy Configuration, as well as the Basic Audit Policy Configuration? The event IDs are different, but this is a Microsoft built in option since Server 2008R2. Event IDs 4624, 4634 w/ Advanced vs. 6948, 6749 w/ Basic
Here's a link on the differences between the two.
Advanced Security Auditing FAQ
Thanks,
Pat