Has anyone setup reporting for AD login/logout information? I have a customer who wants a report of when a user logs in and out every day.


I personally have not used the reporting Enterprise feature .
As @gsmith mentioned, reporting is a Enterprise feature.

An alternative (free) way would be alerts and notification. You can find the event IDs for AD login/logoff (for the alert search query Alerts — Graylog 4.1.0 documentation) at the Microsoft Documentation webpage (e.g. Audit Logon (Windows 10) - Windows security | Microsoft Docs / Audit Logoff (Windows 10) - Windows security | Microsoft Docs).

