wevtutil gp Microsoft-Windows-Security-Auditing /ge:true /gm:true /f:xml > junk.xml
Page down through junk.xml until you get to the event IDs