Windows Security Log Event ID 682

Operating Systems Windows Server 2000
Windows 2003 and XP
Type Success
Corresponding events
in Windows 2008
and Vista

682: Session reconnected to winstation

On this page

Windows logs this event when a user reconnects to a disconnected terminal server session as opposed to a fresh logon which is reflected by event 528.

User Name and Domain identify the user of the remote desktop connection that was reconnected to.

Logon ID corresponds to the logon id specified in an earlier event 528. See 528 for more details.

Client Name specifies the computer name of the client computer while Client Address specifies its IP address.

Free Security Log Resources by Randy

Description Fields in 682

  •  User Name: %1
  •  Domain:  %2
  •  Logon ID:  %3
  •  Session Name: %4
  •  Client Name: %5
  •  Client Address: %6

Setup PowerShell Audit Log Forwarding in 4 Minutes


Examples of 682

Session reconnected to winstation:
User Name:administrator
Logon ID:(0x0,0xBBA2)
Session Name:RDP-Tcp#5
Client Name:CPQ
Client Address:

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources