Windows "Explicit" logins (EID 4648) are logins to a remote system that are recorded on the originating system. These logons are represented in the UI with a status of "UNKNOWN", as the Windows Explicit logon record does not include an indication of success or failure. Think of a Windows Explicit logon as the OS recording "I can't tell you what happened, but someone on this system tried to log into this other system". What's particularly interesting about these logons is that the process that attempted the login is recorded (PowerShell, cscript, IIS, documents, browsers). To review these logins:
Filter on category "unknown" and/or status "unknown"
Open the Graph Filter
Review the unique "process"