it appears that the usual AD-attribute lastLogonTimeStamp is not yet implemented in Samba 4.
But it looks like that you can derive some informations from /var/log/auth.log.
I can see entries like these on the DC:
Apr 20 10:11:36 master PAM-univentionsambadomain: continuing as user username
Apr 20 10:11:36 master smbd: pam_unix(samba:session): session opened for user username by (uid=0)
Apr 20 10:11:48 master smbd: pam_unix(samba:session): session closed for user DOM+username