Event ID - 4647

Event Id4647
SourceMicrosoft-Windows-Security-Auditing
DescriptionUser initiated logoff:

Subject:
      Security ID:<Security ID>
      Account Name:<Account Name>
      Account Domain:<Domain Name>
      Logon ID:<Logon ID>     

Event InformationCause :
This event is generated when a logoff is initiated but the token reference count is not zero and the logon session cannot be destroyed. No further user-initiated activity can occur. This event can be interpreted as a logoff event.
Resolution :
NO user action is required.
Reference Links

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.