I think you are now down to picking one of two options.
- Enable logging on the TMG server
- Use something like LANGuardian to capture the user, IP, proxy, website, and volumes from network traffic.
My own area of expertise is packet capture so I may be missing something. Hopefully other Thwack members might post here if there is another option
Darragh