It is recorded, if you go to the event viewer on the domain controller and select security, look for the Logon/LogOff category, and you'll see the user name and you can probably discern which event is for log off / on. If it was 2008 you could filter it, otherwise you'll probably have to get a 3rd party app.