At a bare minimum, this information is written to /var/log/audit if MCP and tmsh Audit Logging is enabled.
AUDIT - user bob - RAW: sshd(pam_audit): user=bob(bob) partition=[All] level=Administrator tty=ssh host=192.168.1.1 attempts=1 start="Sat Jul 4 08:10:16 2015" end="Sat Jul 4 08:10:42 2015".
This tells you who (bob), when it started (Sat Jul 4 08:10:16 2015), when it ended (Sat Jul 4 08:10:42 2015), and how the system was accessed (sshd(pam_audit)). A web GUI user logon would show "httpd(mod_auth_pam)". And as long as console users are only given TMSH access, that information is also recorded.