I don't think this is an instance of something just being enumerated again. A couple of fields to look at in those events. First, the ChangeDetails field shows that failure auditing was removed, meaning that it was enabled previously. What that means is that you will no longer get failure events for those categories. Assuming that success auditing is still enabled, you would still see successful events in those categories. Second, the fact that the SourceAccount field shows the local machine account indicates that this change came from a GPO.
Another alternative may be that someone turned on failure auditing for all of those categories and, when group policy refreshed, it overwrote it back to the standard GPO settings. In this case, you should see events in LEM for failure auditing being enabled for these categories.
I would start digging into my GPOs to see which one caused this change as well as looking for events in LEM for changes in group policy, assuming you are logging those.