A sample active directory log 2008 looks as follows:

Active Directory columns involves having an event ID, an event description, the source of the log and the destination, the network information, the name of the local computer, the log source name, and many more.
For the purposes of the experiment, we will use the following event IDs:
|
Event ID |
Event Description |
|
4624 |
An account was successfully logged on. |
|
4768 |
A Kerberos authentication ticket (TGT) was requested. |
|
4769 |
A Kerberos service ticket was requested. |
|
4672 |
Special privileges was assigned to a new logon. |
|
4776 |
The domain controller attempted to validate the credentials for an account. |
|
4663 |
An attempt was made to access an object. |
We need to keep an account of source and destination for the preceding event IDs. We keep track of user IDs, multiple user logons, and network preferences.