Event ID - 538

Event Id538
DescriptionUser Logoff:

User Name: <user name>
Domain: <domain>
Logon ID: <logon id>
Logon Type: <logon type>
Event InformationAccording to Microsoft :
Cause :
This event record indicates that a user has logged off.
Resolution :
This is an information event and no user action is required.


This is an Event generated, when a user logs off the computer at the NT console.

Interactive logoff generates Event Id of 538, Logon type 2.

Network logoff,Netuse disconnection,Auto disconnection will generate Event Id 538, Logon type 3.

You may be observed "NT AUTHORITY\ ANONYMOUS LOGIN" in user field of event id 538, this indicates that an application or process authenticated to domain. This does not indicate any security breach.A program or service which may be using  SYSTEM account does not require a username and password (null credentials) and will log this type of event description.
Reference LinksEvent ID 538 from Source Security

Alternate Event ID in Vista and Windows Server 2008 is 4634.

Additional Info

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.