You can set up filters in your logger, to filter all logins, and attempts. Such as rsyslog, syslogk, syslogd, syslog-ng
The usual location for the filter is located at /var/log/auth.log If you don't have this, then you need to check your logging configuration config file.
As for grepping, you could grep the string "uid=" or the username. It sounds like homework to me, so I wont give the command to do this. Try looking at the man pages on grep, and look at examples by searching this site.