Vigilio monitoring guide

Track RDP Logins, Logouts and Windows Access Events

Vigilio collects relevant Windows access events so administrators can review who connected, when the event occurred and which source IP was recorded when available.

What RDP login monitoring means

RDP login monitoring is the collection and review of Windows authentication and session events associated with Remote Desktop access. It helps administrators answer practical questions after a support case or incident: who logged in, when did the session start, when did it end and what source IP address was recorded?

👤

Username

Identify the Windows account associated with the event.

🕒

Timestamp

Review when a login, logout or failed-login event occurred.

🌐

Source IP

See the connection source when Windows provides it for the event.

RDP event history versus RDP availability monitoring

FunctionWhat it tells you
TCP monitoring of port 3389Whether the RDP service port is reachable from the monitoring location.
RDP login-event historyWhich Windows account logged in or out and when the event occurred.
Synthetic RDP login testingWhether a complete automated RDP login succeeds. Vigilio does not currently provide this function.

These functions solve different problems. A reachable port does not prove that a user can complete an RDP login, and an access-event log does not continuously test service availability.

How Vigilio collects the events

  1. Install the Vigilio Windows agent on the monitored server.
  2. The agent reads the relevant Windows access events.
  3. Events are sent to the Vigilio service and associated with the monitored server.
  4. The dashboard displays event type, username, timestamp and source IP when available.
Privacy and retention: access logs can contain personal or security-relevant information. Define who may view the dashboard and how long event history should be retained under your internal policy.

Useful RDP monitoring scenarios

Investigating an unexpected server change

Compare the time of the change with recent RDP login and logout events to identify which accounts were active around the incident.

Supporting multiple client servers

Review access history without opening Event Viewer on each individual server.

Checking administrative access

Confirm whether an administrator connected during a maintenance window and which source IP was recorded.

What Vigilio does not claim

RDP event history is not a security guarantee. Vigilio does not replace MFA, VPN access controls, account lockout policies, endpoint protection, firewalls or a SIEM. It provides focused visibility that can support administration and incident review.

Monitor it with Vigilio

Create an account, add an external check or install the Windows agent, and receive Telegram alerts for operational incidents.

Related monitoring pages

FAQ

Frequently asked questions

The agent collects supported Windows login, logout and failed-login events. The exact data available can depend on Windows logging and the event itself.

Yes, when the corresponding Windows event contains a source address. Some local or system events may not include a meaningful remote IP.

No. Access-event monitoring records real Windows events. A TCP monitor can separately check whether the RDP port is reachable.

The product is designed to associate events with a monitored server and user data. Available filtering should match the current dashboard implementation.

Failed-login events can currently be reviewed in the dashboard. Dedicated Telegram alerts for failed logins and brute-force patterns are not currently included.