You could check the logon information in event log. u can enable auditing for account logon events. These
events (including workstation unlock) will be stored in the DC's security log.
https://technet.microsoft.com/en-us/library/cc787567%28WS.10%29.aspx?f=255&MSPPError=-2147217396
you can record log on activity through group policy as well.. follow below page..
http://social.technet.microsoft.com/wiki/contents/articles/20422.record-logon-logoff-activities-on-domain-servers-and-workstations-using-group-policy.aspx
Here is a similar thread discussed before. Maybe you could refer to.