when diving into the data, it looks like the authentication data model is returning two events for one actual login. It looks like the event to get permission from the domain controller, is recorded and then the actual login to the computer is logged.
Is this normal, incorrect windows setup, or bad datamodel?
Thank you,
Rick
↧