Free tools Windows power users keep installed
One-click scans. No signup required.
Sometimes—but the Windows Security log is not a record of every website login. For a site using Windows-integrated authentication on IIS, check the IIS server’s Event Viewer > Windows Logs > Security log for events such as 4624 (successful Windows logon) and 4625 (failed logon). A 4624 records a Windows logon session on that server; by itself, it does not prove that someone signed in to an arbitrary website.
First determine where the website authenticates users
The right log depends on the site’s authentication method. With Windows-integrated authentication on IIS, start at the IIS host: Windows generates a network-resource logon event on the computer hosting the resource. Microsoft’s IIS troubleshooting example uses the server’s Security log to examine Windows authentication events.
Other sites may authenticate users through application-managed accounts, a federated identity provider, or another non-Windows mechanism. In those cases, the relevant sign-in record may be in the application or identity provider’s logs rather than the Windows Security log. The Windows event documentation does not establish that every website authentication method produces a corresponding Windows logon event.
How to check an IIS server’s Security log
- Identify the authenticating host. For the documented Windows-integrated IIS scenario, use the IIS server handling the request.
- Open Event Viewer on that server. Go to Event Viewer > Windows Logs > Security.
- Find the relevant time window and event IDs. Review 4624 for a successful Windows logon session and 4625 for a failed logon. Consider event 4648 if the investigation involves explicitly supplied credentials.
- Inspect the event’s details. In a 4624, examine the New Logon account, Logon Type, Source Network Address and port if present, Process Information, Logon Process, and Authentication Package. Use the event time, server, account, and surrounding records to establish context.
- Correlate related records when available. Logon ID or Logon GUID can help link events, but their usefulness depends on whether the relevant records and identifiers are present.
Microsoft’s IIS/Kerberos troubleshooting scenario shows a 4624 on the target IIS server with logon type 3, an account in New Logon, a client source address, and Kerberos authentication details. That is an example of Windows-integrated authentication, not a template that every website login must match. Microsoft’s IIS/Kerberos troubleshooting scenario
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
- There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
- Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
- Reorder SKU: LOG-100-M3CW-PP(Security-Report)
What the main event IDs mean
| Event ID | What it records | How to use it |
|---|---|---|
| 4624 | A successful Windows logon; a logon session was created on the computer that was accessed. | Inspect the account, logon type, and authentication context. It is not universal proof of a website login. |
| 4625 | A failed Windows logon attempt. | Use it when investigating unsuccessful Windows authentication. |
| 4648 | A logon attempt using explicitly supplied credentials. | Correlate it with other evidence; it describes an attempt, not necessarily a successful session. |
| 4634 | An account was logged off. | Can help identify session termination. A shutdown without a proper logoff can make logoff auditing incomplete. |
| 4647 | A user initiated logoff. | Distinguish user-initiated logoff from the broader account logoff record. |
Microsoft describes 4624 as an event generated when a logon session is created on the destination computer. See the 4624 event reference and Advanced Audit Policy Configuration settings.
How to interpret the fields in a 4624
- New Logon account: identifies the account associated with the newly created session. Read it with the host and time; an account in the event does not independently establish which website page or application action was involved.
- Logon Type: describes the Windows logon context. In Microsoft’s IIS/Kerberos example, the event uses type 3, a network logon. Do not assume all website access produces that type.
- Source Network Address and port: may help identify the originating network endpoint when populated. Their presence depends on the protocol and authentication context.
- Process Information and Logon Process: provide context about the process and logon path associated with the event.
- Authentication Package: indicates the authentication mechanism represented in the Windows event; Microsoft’s cited IIS example uses Kerberos.
- Logon ID or Logon GUID: may help correlate related events when those identifiers are available in the relevant records.
Do not treat blank workstation or network fields as proof that no client connected. Microsoft notes that available details depend on protocol and context: for example, Kerberos network logons may not include workstation information, while NTLM logons may lack TCP/IP details. The 4624 reference documents the event fields and these qualifications.
Rank #2
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Why a website login may not appear there
The Security log records Windows authentication sessions on the computer handling the authentication—not a universal history of website account activity. A website may accept credentials in its own application, delegate sign-in to an identity provider, or use another authentication flow that does not create the Windows event you are looking for. For those systems, consult the application or identity provider’s sign-in logs. Even when a 4624 is relevant, it does not identify every page visited or establish all activity within a web session.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.For administrators: check auditing and collection
Whether the expected records are available depends on audit policy and log collection. Microsoft’s Audit Logon documentation describes the audit purpose and related event IDs; verify that the applicable policy is configured on the system whose authentication you need to monitor. Event Viewer is suitable for a local investigation, while centralized monitoring requires a collection pipeline configured to retain the relevant events.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
- SHIRT POCKET SIZE: 5" x 3.5" designed to fit in an officer uniform shirt front pocket for easy access. Palm sized notebook makes it easier to write directly in your hand in while on the go
- STAY ORGANIZED: This tactical note pad has all you need to stay organized and remember to get all important information
- PROFESSIONAL POLICE EQUIPMENT: Perfect for new patrol officers, security guards, detectives, private investigators case investigator or public safety accessories
- STURDY DESIGN: Updated to a thicker backing for easier writing in your palm. This double spiral book is designed to line up when to flipped over for sturdy writing one handed. 70 sheets (140 pages) will last you a long time
- MORE FOR THE PRICE: Dual page design with a citation box style from on front and notes on the back allows you to capture all information
For Microsoft Sentinel, the documented Windows security event sets include 4624 and 4625 in both the Minimal and Common sets. Check the Windows security event sets reference when configuring collection; the available sets and product guidance can change.
Microsoft’s event semantics and audit references cited here are in its Windows documentation, including previous-version Windows 10 event pages. Apply them to the Windows version and audit configuration in use rather than assuming every deployment is identical.
Quick Recap
Best Value
- Hardcover journal with 240 line-ruled pages (120 sheets)
- Built-in elastic closure and ribbon bookmark
- Includes an expandable inner storage pocket and a pen holder
Rank #4
- THE IDEAL SIZE - The field interview and incident report notebook is a slim 3.75” x 6” pocket sized police notebook that fits easily and comfortably in a uniform pocket
- TAKE NOTES ON THE GO - This professional reporter’s notebook makes it easy taking notes in the field. we use a .75mm thick cover, twice as rigid as most competitors. The extra stability provides a sturdy writing surface, so you are always prepared
- FORM KEEPS YOU ORGANIZED - This notebook includes a simple, yet comprehensive form for recording key notes, ensuring you don’t miss important details. Each report has individual sections for case numbers, time, date, location, etc
- DURABLE CONSTRUCTION - Our appointment planners are made with extra thick covers, bound with coated spiral bindings, and rounded page corners, that make for a professional and durable notebook that stands the test of time. Portage is built to last
- TRIED AND TESTED DESIGN - Our Notepads have been tested and perfected by the professionals that use them daily. This notebook has been designed to keep all cases and information organized and accessible
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

