Session disconnected from winstation
On this page
Windows logs this event when a user disconnects from a terminal server (aka remote desktop) session as opposed to an full logoff which triggers event 538.
User Name and Domain identify the user of the remote desktop connection that was reconnected to.
Logon ID corresponds to the logon id specified in an earlier event 528. See 528 for more details.
Client Name specifies the computer name of the client computer while Client Address specifies its IP address.
Free Security Log Quick Reference Chart
Top 10 Windows Security Events to Monitor
Session disconnected from winstation:
Keep me up-to-date on the Windows Security Log.
*We will NOT share this
Go To Event ID: