The Windows security log event IDs worth knowing: logons, lockouts, Kerberos, Get-WinEvent queries and how to turn auditing on!