Log in to any computer with domain IT admin privileges → Run Command Prompt as an administrator → Type gpresult /S <monitored computer> /F /H <file name>.HTML → Navigate to C:\Users\<logged in user><file name.HTML> to check if all the audit policy settings and security logs settings are in place.
Refer to section four (4) found in this document.
Log in to any computer with domain admin privileges → Go to Run, and type eventvwr.msc → Right-click on Event Viewer, and connect to the target computer → Check if the corresponding event numbers are present.