Hi, We have just installed Directory Monitor v.1.10.41 after using the AD_Login Script for many years. (Windows Server 2016 - Single AD)

All seems to be going well, but I just got a couple of questions,

1/ I now see a variety of LOGIN events, i.e. AUTHENTICATE and UPDATE for all users but I can't see any pattern as to what specifically triggers each event. In the api Event log, both show as a LOGIN_TYPE of "A". What differentiates UPDATE vs. AUTHENTICATE ?

2/ I was hoping to see logoff events as some users tend to logon to the domain at several PC's. I updated System Audit Policies ==> Local Group Policy Object ==> Account Logon in Local Policies but Logoffs don't seem to show. Should I be expecting seeing Logoff events ?

Thanks .. Wayne R.