Windows Security Log Event ID 4647
Operating Systems Windows Vista
Windows Server 2008
Category
 • Subcategory
Logon/Logoff
 • Logoff
Type Success
Corresponding events
in Windows 2003
and before
551  
Discussions on Event ID 4647

4647: User initiated logoff

On this page

Also see 4634. This event signals the end of a logon session and can be correlated back to the logon event 4624 using the Logon ID.
This event seems to be in place of 4634 in the case of Interactive and RemoteInteractive (remote desktop) logons.  This is a plus since it makes it easier to distinguish between logoffs resulting from an idle network session and logoffs where the user actually logs off with from his console.

Free Security Log Quick Reference Chart

Subject:

  •  Security ID:  %1
  •  Account Name:  %2
  •  Account Domain:  %3
  •  Logon ID:  %4

Top 10 Events to Monitor

User initiated logoff:

Subject:
  
Security ID:  WIN-R9H529RIO4Y\Administrator
   Account Name:  Administrator
   Account Domain:  WIN-R9H529RIO4Y
   Logon ID:  0x19f4c


This event is generated when a logoff is initiated but the token reference count is not zero and the logon session cannot be destroyed.  No further user-initiated activity can occur.  This event can be interpreted as a logoff event.

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this

Security Log Resource Kit

The Security Log Resource Kit includes:

  • Book
  • Interactive Course
  • Poster
  • Encyclopedia