As I currently understand it, I don't think you can do this with ePO/MAgent? I've had a look through the client Event IDs this morning and cannot see any that would be triggered for user login events.
ePO was never intended to be a AD or some sort of SIEM for tracking event information like that. You'd be better off trying to use SCCM or if your organization has a SIEM to collect the log information and query for it from there.
However, you might be able to do this through ePO.. I see event IDs:
20789: User Logged On
20790: User Logon Failed
20791: User Logged Off
You might be able to setup some tracking for that and use those IDs for automatic responses, but again, there are more efficient methods than using ePO if available to you.
There are a couple of way to go about it. If you want to utilize ePO however try the following, as I have on multiple occasions
( Utilize Tagging)
1. after you gain the paremters, Usernames, host names etc. Create a tag in ePO
2. Go into the SIEM, and create an alarm, which has a trigger of an signature ID, or correlation rule that state, when bob logs on to hostA, while user mary is logged on, assign the ePO tag and send me an email.
3. Take it farthur, by, running a script (powershell or whatever), and solicit all forensic info from the host of both Host machines. I use POSH