#user-logoff
3 articles
Windows Events3
Windows Event ID 4109 – Microsoft-Windows-Wininit: User Logoff Notification
Event ID 4109 records user logoff events initiated by the Windows initialization process, providing audit trail for session termination and system security monitoring.

Windows Event ID 4647 – Microsoft-Windows-Security-Auditing: User Initiated Logoff
Event ID 4647 records when a user initiates a logoff from a Windows session. This security audit event tracks user-initiated disconnections for compliance and security monitoring purposes.

Windows Event ID 4634 – Microsoft-Windows-Security-Auditing: An Account Was Logged Off
Event ID 4634 records when a user account logs off from a Windows system. This security audit event tracks logoff activities for compliance and security monitoring purposes.