Select the product you need help with
The User Logoff Event ID 538 Is Not Logged to the Security Event Log When You Shut Down Your Computer and Then Restart ItArticle ID: 828857 - View products that this article applies to. SYMPTOMSIf you configure an audit policy to audit successful logon and logoff events, you may find that the user logoff audit event ID 538 is not logged to the security event log after you shut down your computer and then restart it. CAUSEThis behavior occurs because during the shutdown process, the service that writes to the security event log is already stopped when the last token for the user who logs off is released.
As a result, the user logoff audit event ID 538 is not logged to the security event log when you shut down your computer and then restart it. This behavior is by design. WORKAROUNDTo work around this behavior, configure an audit policy to audit successful system events. To do this, follow these steps on the local computer. Note Because there are several versions of Microsoft Windows, the following steps may be different on your computer. If they are, see your product documentation to complete these steps.
Type: Success Audit Type: Success Audit PropertiesArticle ID: 828857 - Last Review: October 30, 2006 - Revision: 1.2 APPLIES TO
|


Back to the top








