Here's a couple of lines from /var/log/audit/audit.log:
type=USER_START msg=audit(1459948449.045:128516): user pid=9482 uid=10011713 auid=10011713 ses=7110 msg='op=PAM:session_open acct="root" exe="/bin/su" hostname=? addr=? terminal=pts/1 res=success'
type=CRED_ACQ msg=audit(1459948449.045:128517): user pid=9482 uid=10011713 auid=10011713 ses=7110 msg='op=PAM:setcred acct="root" exe="/bin/su" hostname=? addr=? terminal=pts/1 res=success'
The other logs (/var/log/secure, /var/log/messages) are as you describe.
I guess I'll have to limit log collection to those two logs.
Thanks