Event ID: 4634
Log Name: Security
Source: Microsoft Windows security auditing
Message: An account was logged off.
4624
Successful logon
Security
4647
User initiated logoff (explicit)
4634
Logoff (session ended)
4779
Session disconnect (Remote)
1074
Shutdown/restart initiated by user or process
System
Use 4647 if you want to track logoffs that were explicitly initiated by the user (e.g., clicking “Log Off”), and 4634 for any type of session termination (timeout, RDP close, etc.).
Open Event Viewer (eventvwr.msc)
eventvwr.msc
Go to Windows Logs > Security
Use Filter Current Log… on the right
Filter by Event IDs: 4634, 4647, 4779
4634, 4647, 4779
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4634arrow-up-right
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/basic-audit-logon-eventsarrow-up-right
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/basic-security-audit-policy-settingsarrow-up-right
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4779arrow-up-right
Last updated 7 months ago