System32
Sysmon
Events
Compliance
Validator
TLS/SSL
GeoIP
Tools
Windows Security Events
Audit Category
Logon/Logoff
(2)
Operating Systems
Windows 10
(2)
Windows 2008
(2)
Windows 2008 R2
(2)
Windows 2012
(2)
Windows 2012 R2
(2)
Windows 2016
(2)
Windows 2019
(2)
Windows 2022
(2)
Windows 2025
(2)
Windows 7
(2)
Windows 8
(2)
Windows 8.1
(2)
Windows Vista
(2)
Tags
Audit Success
(2)
Auditing
Conditional
(2)
Volume
High
(2)
Low
(2)
Medium
(1)
Audit Subcategory
Logoff
(2)
AppLocker
All AppLocker events
EventSentry
All EventSentry events
Security
All Windows Security events
Sysmon
All Sysmon events
ID
Event Description
4634
An account was logged off
Audit Success
4647
User initiated logoff
Audit Success