LogoutEventStream

Tracks user UI logout. A logout event records a successful user logout from your org’s UI. This object is read only, and you can’t retrieve it using a SOQL query. This object is available in API version 41.0 and later.

When LogoutEventStream is enabled, Salesforce publishes logout events, and you can add an Apex trigger to subscribe to those events. You can then implement custom logic during logout. For example, you can revoke all refresh tokens for a user at logout.

LogoutEventStream records logouts, not timeouts. Timeouts don’t cause a LogoutEventStream object to be published. An exception is when a user is automatically logged out of the org after their session times out because the org has the Force logout on session timeout setting enabled. In this case, a logout event is recorded. However, if users close their browser during a session, regardless of whether the Force logout on session timeout setting is enabled, a logout event isn’t recorded.

Note

Supported Calls 

describeSObjects()

Special Access Rules 

As of Summer ’20 and later, only users with the Customize Application user permission can access this object.

Supported Subscribers 

SubscriberSupported?
Apex TriggersYes
Flows 
Processes 
Pub/Sub APIYes
Streaming API (CometD)Yes

Subscription Channel 

/event/LogoutEventStream

Event Delivery Allocation Enforced 

No

Fields 

EventDate 

Type: datetime

Properties: Nillable

Description: Represents when the event started. For example, 2020-01-20T19:12:26.965Z. Milliseconds are the most granular setting.

EventIdentifier 

Type: string

Properties: Nillable

Description: The unique ID of the event, which is shared with the corresponding storage object. For example, 0a4779b0-0da1-4619-a373-0a36991dff90. Use this field to correlate the event with its storage object.

EventUuid 

Type: string

Properties: Nillable

Description: A universally unique identifier (UUID) that identifies a platform event message. This field is available in API version 52.0 and later.

LoginKey 

Type: string

Properties: Nillable

Description: The string that ties together all events in a given user’s login session. It starts with a login event and ends with either a logout event or the user session expiring.

RelatedEventIdentifier 

Type: string

Properties: Nillable

Description: Represents the EventIdentifier of the related event.

ReplayId 

Type: string

Properties: Nillable

Description: Represents an ID value that is populated by the system and refers to the position of the event in the event stream. Replay ID values aren’t guaranteed to be contiguous for consecutive events. A subscriber can store a replay ID value and use it on resubscription to retrieve missed events that are within the retention window.

SessionKey 

Type: string

Properties: Nillable

Description: The user’s unique session ID. You can use this value to identify all user events within a session. When a user logs out and logs in again, a new session is started.

SessionLevel 

Type: picklist

Properties: Nillable, Restricted picklist

Description: Indicates the session-level security of the session that the user is logging out of for this event. Session-level security controls user access to features that support it, such as connected apps and reporting. Possible values are:

  • HIGH_ASSURANCE—A high assurance session was used for resource access. For example, when the user tries to access a resource such as a connected app, report, or dashboard that requires a high-assurance session level.
  • LOW—The user’s security level for the current session meets the lowest requirements.
  • STANDARD—The user’s security level for the current session meets the Standard requirements set in the org’s Session Security Levels.

This low level is not available, nor used, in the Salesforce UI. User sessions through the UI are either standard or high assurance. You can set this level using the API, but users assigned this level experience unpredictable and reduced functionality in their Salesforce org.

Note

SourceIp 

Type: string

Properties: Nillable

Description: The source IP address of the client logging out. For example, 126.7.4.2.

UserId 

Type: reference

Properties: Nillable

Description: Represents the ID of the user associated with the logout event.

Username 

Type: string

Properties: Nillable

Description: Represents the username of the user associated with the logout event.

Usage 

In this example, the subscriber inserts a custom logout event record during logout.

1trigger LogoutEventTrigger on LogoutEventStream (after insert) { 
2  LogoutEventStream event = Trigger.new[0];
3  LogoutEvent__c record = new LogoutEvent__c();
4  record.EventIdentifier__c = event.EventIdentifier;
5  record.UserId__c = event.UserId;
6  record.Username__c = event.Username;
7  record.EventDate__c = event.EventDate;
8  record.RelatedEventIdentifier__c = event.RelatedEventIdentifier;
9  record.SessionKey__c = event.SessionKey;
10  record.LoginKey__c = event.LoginKey;
11  insert(record);
12}