Security Logs Windows 2008 R2
4740 – Account lockout, (giving user and the workstation thats actually locking out the account.)
5136 – Group policy links added or deleted
2013 – disk space at or near exhaustion
4727 – A security-enabled global group was created.
4728 – A member was added to a security-enabled global group.
4730 – A security-enabled global group was deleted.
4731 – A security-enabled local group was created.
4732 – A member was added to a security-enabled local group.
4733 – A member was removed from a security-enabled local group.
4734 – A security-enabled local group was deleted.
4735 – A security-enabled local group was changed.
4737 – A security-enabled global group was changed.
4754 – A security-enabled universal group was created.
4755 – A security-enabled universal group was changed.
4756 – A member was added to a security-enabled universal group.
4757 – A member was removed from a security-enabled universal group.
4758 – A security-enabled universal group was deleted.
You can trawl for these events using the microsoft provided EventCombMT.exe – however the security log option will be GREYED out unless you run as administrator.
More details below..
http://support.microsoft.com/kb/947226