Event Details
Operating System->Microsoft Windows->Built-in logs->Windows 2000-2003->Security Log->Logon/Logoff->EventID 538 - User Logoff
EventID 538 - User Logoff
Indicates that a user has successfully ended a logon session (a network connection to a file share, interactive logon, or other logon type), in other words logged off.

Note:
If you configure an audit policy to audit successful logon and logoff events, you may find that the user logoff audit event ID 538 is not logged to the security event log after you shut down your computer and then restart it.
This behavior occurs because during the shutdown process, the service that writes to the security event log is already stopped when the last token for the user who logs off is released. As a result, the user logoff audit event ID 538 is not logged to the security event log when you shut down your computer and then restart it. This behavior is by design.

Find more information about this event on ultimatewindowssecurity.com.

Corresponding events on other OS versions:


Windows 2008

     Sample:
            Event Type:     Success Audit
            Event Source:   Security
            Event Category: Logon/Logoff
            Event ID:       538
            Date:           10/26/2009
            Time:           07:31:44
            User:           NT AUTHORITY\SYSTEM
            Computer:       DC1
            Description:
            User Logoff:
            User Name:	DC1$
            Domain:		RESEARCH
            Logon ID:		(0x0,0x60FA64)
            Logon Type:	3
          
    Log Type: Windows Event Log
     Uniquely Identified By:
    Log Name: Security
    Filtering Field Equals to Value
    OSVersion Windows 2000
    Windows XP
    Windows 2003
    Source Security
    Category Logon/Logoff
    EventId 538
    Field Matching
    FieldDescriptionStored inSample Value
    DateTime Date/Time of event origination in GMT format. DateTime 10.10.2000 19:00:00
    Source Name of an Application or System Service originating the event. Source Security
    Type Warning, Information, Error, Success, Failure, etc. Type Success
    User Domain\Account name of user/service/computer initiating event. User RESEARCH\Alebovsky
    Computer Name of server workstation where event was logged. Computer DC1
    EventID Numerical ID of event. Unique within one Event Source. EventId 576
    Description The entire unparsed event message. Description Special privileges assigned to new logon.
    Log Name The name of the event log (e.g. Application, Security, System, etc.) LogName Security
    Category A name for a subclass of events within the same Event Source. Category Logon/Logoff
    Domain Domain of the account for which logon is requested. InsertionString2 RESEARCH
    Logon ID ID of the logon session of the successfully logged in user. Useful for tracking other user activity within the same logon session. InsertionString3 (0x0,0x60FA64)
    Logon Type Interactive, Network, Batch, etc. Please find the code descriptions here. InsertionString4 3
    User Name Name of the account that initiated the action. InsertionString1 DC1$
    Comments
    You must be logged in to comment