Event ID 538 – User Logoff
|Description||Successful user logoff|
Whenever a user logs off, regardless of the logon type, event 538 is generated. This only indicates that the user has successfully ended a logon session, and does not reliably track user logoff events.
This log data provides the following information:
- User Name
- Logon Type
- Logon Process
Note: When a computer is shut down and restarted, event 538 is not entered into the security event log, as the service which writes to the event log is already stopped. This is an example of how user logoff events cannot be tracked reliably.
With in-depth reports, real-time alerts, and graphical displays, ADAudit Plus tracks all user logoffs, helping you meet your security, operational, and compliance needs with absolute ease.
Event 538 applies to the following operating systems:
- Windows Server 2000
- Windows 2003 and XP
Corresponding event ID in Windows 2008 and Windows Vista is 4634.