Event ID 538 – User Logoff
Event ID | 538 |
Category | Logon/Logoff |
Type | Success Audit |
Description | Successful user logoff |
Whenever a user logs off, regardless of the logon type, event 538 is generated. This only indicates that the user has successfully ended a logon session, and does not reliably track user logoff events.
This log data provides the following information:
- User Name
- Domain
- Logon Type
- Logon Process
Note: When a computer is shut down and restarted, event 538 is not entered into the security event log, as the service which writes to the event log is already stopped. This is an example of how user logoff events cannot be tracked reliably.
Pro Tip:
With in-depth reports, real-time alerts, and graphical displays, ADAudit Plus tracks all user logoffs, helping you meet your security, operational, and compliance needs with absolute ease.
Event 538 applies to the following operating systems:
- Windows Server 2000
- Windows 2003 and XP
Corresponding event ID in Windows 2008 and Windows Vista is 4634.
Explore Active Directory auditing and reporting with ADAudit Plus.
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools