We don't use all the aspects of AD Audit Plus, just a select few. Most of the reports we need work fine from the audit configs we have. However, under "User Logon Reports", LOgon Failures, Logon Failures based on users, failures due to Bad Password, Failures due to Bad User Name, and Day based Logon Errors, all give us "No Data Available". What are the data sources for those reports? (ie are they events from workstations, member servers, or DCs? what are the event IDs these are based on?)
Our local logon-logoff reports seem to work fine, and I'm not sure what the difference in the reports is.