On any Windows server I've worked on over the years, the security log has always been chock full of 'success audit' entries, and I've then had to filter down and remove the successes. I think only ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results