In the event log Windows stores events that happened on the computer. For example - who has logged into your computer and when.
First start Event Viewer.
Then find the Security log and scan for interesting events.
Using the Filter Current Log... feature it is possible to only display events of a certain type.
To catch all logon events there is a setting in the group policy to activate auditing of these. Start up gpedit and change Computer Configuration / Windows Settings - Security Settings - Local Policies - Audit Policy - Audit login events. This is the setting you wish to change:
Audit both Success and Failure.
It should look like this after you are done: