Account auditing lets you monitor logon events that occur on your computer. For example, you can use account auditing to monitor whether anyone tries to log into your computer using your user account. When an account logon event occurs, Windows 7 writes the event to a log file. You can view the contents of the log file through Event Viewer.
To turn on account auditing in Windows 7:
- Click Start, type secpol.msc and press Enter.
- Within the Local Security Policy, expand Local Policies and click Audit Policy.
- Within the Details pane, right click the Audit account logon events policy option and click Properties.
- Check both the Success and Failure options.
- Click OK.
Complete the steps above again, only in step 3, select the Audit logon events option. By enabling this option, Windows 7 tracks both success and failure of any local or remote access-based logon.