Hello Shafiq, Majid,
Thank you for posting in our Q&A forum.
1.The main difference with “4634(S): An account was logged off.” event is that 4647 event is generated when logoff procedure was initiated by specific account using logoff function, and 4634 event shows that session was terminated and no longer exists.
You can check Account Name under Subject, who logoff the local administrator account.
https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4647
2.Also, is your machine in one domain or not? If so, when you change aonther local account, check if you have the same issue.
3.If your machine is one domain, you can try to remove it from the domain and check if there is still such issue.
4.Check if there is any script or schedule that does this thing.
Hope the information above is helpful. If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.