Log Name: Security Source: Microsoft-Windows-Security-Auditing Date: 10/27/2009 9:52:19 PM Event ID: 4647 Task Category: Logoff Level: Information Keywords: Audit Success User: N/A Computer: dcc1.Logistics.corp Description: User initiated logoff: Subject: Security ID: S-1-5-21-1135140816-2109348461-2107143693-500 Account Name: Administrator Account Domain: LOGISTICS Logon ID: 0x1806d9 This event is generated when a logoff is initiated but the token reference count is not zero and the logon session cannot be destroyed. No further user-initiated activity can occur. This event can be interpreted as a logoff event.