Article ID: 828857 - Last Review: October 30, 2006 - Revision: 1.2 The User Logoff Event ID 538 Is Not Logged to the Security Event Log When You Shut Down Your Computer and Then Restart It
SYMPTOMSIf you configure an audit policy to audit successful logon and logoff events, you may find that the user logoff audit event ID 538 is not logged to the security event log after you shut down your computer and then restart it. CAUSEThis behavior occurs because during the shutdown process, the service that writes to the security event log is already stopped when the last token for the user who logs off is released.
As a result, the user logoff audit event ID 538 is not logged to the security event log when you shut down your computer and then restart it. This behavior is by design. WORKAROUNDTo work around this behavior, configure an audit policy to audit successful system events. To do this, follow these steps on the local computer. Note Because there are several versions of Microsoft Windows, the following steps may be different on your computer. If they are, see your product documentation to complete these steps.
Type: Success Audit Type: Success Audit APPLIES TO
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations |






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
