been working with Solarwinds support to no avail. we've tried event ID's 4624 and 4648.
4624 is captured by logging on using the domain\administrator but also includes all chatter from servers and other DC's - several thousand a day. The server and dc "chatter" uses the same ID and account.
"