Windows Security Log Event ID 683
Operating Systems Windows Server 2000
Windows XP
Windows Server 2003
CategoryLogon/Logoff
Type Success
Corresponding events
in Windows 2008
and Vista
4779  
Discussions on Event ID 683
Ask a question about this event

683: Session disconnected from winstation

On this page

Windows logs this event when a user disconnects from a terminal server (aka remote desktop) session as opposed to an full logoff which triggers event 538.

User Name and Domain identify the user of the remote desktop connection that was reconnected to.

Logon ID corresponds to the logon id specified in an earlier event 528. See 528 for more details.

Client Name specifies the computer name of the client computer while Client Address specifies its IP address.

  •  User Name: %1
  •  Domain:  %2
  •  Logon ID:  %3
  •  Session Name: %4
  •  Client Name: %5
  •  Client Address: %6

Top 10 Windows Security Events to Monitor

Session disconnected from winstation:
User Name:administrator
Domain:ELMW2
Logon ID:(0x0,0x5BAA5)
Session Name:Unknown
Client Name:CPQ
Client Address:10.42.42.90

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this



Training for the Windows Security Log