4634 Security log · Logon/Logoff info severity very-high volume

Windows Event ID 4634 — An account was logged off

Logon session terminated. Does not fire for interactive logoffs (see 4647). Primarily covers network and service logons.

Why event 4634 matters

Session duration anomalies (4624 to 4634 delta) can reveal long-running remote sessions. High volume — do not alert individually.

How to detect it

Use 4624+4634 pairs to compute session duration. Sessions >24 h from external IPs warrant review. No standalone alerting.

Log source
Security
Advanced Audit Policy — enable the 'Logon/Logoff' subcategory (Success and/or Failure).
Fields to pivot on
TargetUserNameLogonTypeTargetLogonId

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 4634   // An account was logged off
| project TimeGenerated, Computer, TargetUserName, LogonType, TargetLogonId
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4634
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# An account was logged off — add EventData fields: TargetUserName, LogonType, TargetLogonId`
Hunt event 4634 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Logon/Logoff events

4624 An account was successfully logged on 4625 An account failed to log on 4626 User/Device claims information 4627 Group membership information 4647 User initiated logoff 4648 A logon was attempted using explicit credentials 4649 A replay attack was detected 4672 Special privileges assigned to new logon 4778 A session was reconnected to a Window Station 4779 A session was disconnected from a Window Station 4800 The workstation was locked 4801 The workstation was unlocked

Frequently asked questions

What is Windows Event ID 4634?

An account was logged off. Logon session terminated. Does not fire for interactive logoffs (see 4647). Primarily covers network and service logons.

Which log records event 4634?

Event 4634 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Logon/Logoff' subcategory (Success and/or Failure).

How do you detect activity around event 4634?

Use 4624+4634 pairs to compute session duration. Sessions >24 h from external IPs warrant review. No standalone alerting.