Thnaks for your help!
I have noticed an issue that we didnt have a GPO configured to audit failure logon events and therefore why they won't show in the audit logs of the machines.
Although, do you we need to have the solarwinds LEM windows agent to be installed for each of the workstations before LEM can read their security logs?