Typically I look in the "Security" log in Windows Event Viewer. This will typically have so many entries it is also unusable. Filter on these two event IDs "6272, 6273". Now you can easily see what you want.
I'm also a big fan of "ADAudit Plus". It has a nice GUI and will tell you when your users logged on and off - but also what things they accessed on your network. All in a nice chronological order.
https://www.manageengine.com/products/active-directory-audit/