Logon Logoff Event: 538

Active Directory Auditing Tool

The Who, Where and When information is very important for an administrator to have complete knowledge of all activities that occur on their Active Directory. This helps them identify any desired / undesired activity happening. ADAudit Plus assists an administrator with this information in the form of reports. In real-time, ensure critical resources in the network like the Domain Controllers are audited, monitored and reported with the entire information on AD objects - Users, Groups, GPO, Computer, OU, DNS, AD Schema and Configuration changes with 200+ detailed event specific GUI reports and email alerts.

Logon Logoff » Logon Logoff Event: 538

Event ID 538 – User Logoff

Event ID 538
Category Logon/Logoff
Type Success Audit
Description Successful user logoff

Whenever a user logs off, regardless of the logon type, event 538 is generated. This only indicates that the user has successfully ended a logon session, and does not reliably track user logoff events.

This log data provides the following information:

  • User Name
  • Domain
  • Logon Type
  • Logon Process

Note: When a computer is shut down and restarted, event 538 is not entered into the security event log, as the service which writes to the event log is already stopped. This is an example of how user logoff events cannot be tracked reliably.

Pro Tip:

With in-depth reports, real-time alerts, and graphical displays, ADAudit Plus tracks all user logoffs, helping you meet your security, operational, and compliance needs with absolute ease.

Event 538 applies to the following operating systems:

  • Windows Server 2000
  • Windows 2003 and XP

Corresponding event ID in Windows 2008 and Windows Vista is 4634.