Thanks for the response. The Windows Audit Policy is already set up using our GPO and I verified all the secondary DCs have the correct Audit Policy applied below. Now that I think about it, it could be our firewall.
Policy | Setting |
---|---|
Audit account logon events | Success |
Audit account management | Success, Failure |
Audit directory service access | Failure |
Audit logon events | Success, Failure |
Audit object access | Failure |
Audit policy change | Success, Failure |
Audit privilege use | No auditing |
Audit process tracking | Success, Failure |
Audit system events | Success, Failure |