Submit a ticketCall us

ebook60.pngHow to be a Cisco® ASA ace

Our eBook, Thou Shalt Not Pass…I Think?! can help you overcome the challenges of monitoring and managing Cisco ASA firewalls. This eBook is a great read if you’ve been frustrated with monitoring firewalls, managing ACL configs, and troubleshooting VPN connections.

Get your free eBook.

Home > Success Center > Log & Event Manager (LEM) > Windows Event ID 4634 displays in the LEM Console

Windows Event ID 4634 displays in the LEM Console

Table of contents

Updated: September 28, 2017

Overview

Event ID 4634 displays in the SolarWinds LEM console. 

Environment

  • LEM
  • Windows Agent with security Event log enabled

Detail

Normalized log data for Windows Event ID 4634 displays in the LEM Console, as shown below. 

As displayed above, the following fields are missing data:

  • Destination Account
  • Source Machine
  • Destination Machine

This data may not be applicable for a UserLogOff event. As a result, Microsoft® omitted this data in the Security Event log file. 

See 4634(S): An account was logged off on the Microsoft Docs website for details. 

 

 

Last modified

Tags

Classifications

Public