We are using the Insight Agent and want to forward only specific Windows Security Event IDs from our servers, specifically:
-
4720 – User account created
-
4660 – Object deleted
-
4732 – Member added to a privileged group
-
4726 – User account deleted
how to do this