The below PowerShell script queries a remote computers event log to retieve the event log id’s relating to Logon 7001 and Logoff 7002. Creating a nice little audit of when the computer was logged on and off.

At the bottom of the script you will need to change the computer name and you can change the number of days if required.

The remote computer will need to be online and the “Remote Registry” service needs to be started, this can be done remotely using service.msc and selecting “Connect to another computer” in the actions menu.


The script was origionally posted by Martin Pugh over at SpiceWorks, I also found the Power Shell script over on the TechNet site.