Microsoft | Activate Kerberos Logging
Logging to the eventlogs you can set this via group policy or via cli.
Attached the command you had to use by cli:
German OS: {source}auditpol /set /category:”Kontoanmeldung” /subcategory:”Kerberos-Authentifizierungsdienst” /success:enable /failure:enable{/source}
English OS: {source}auditpol /set /category:”account logon” /subcategory:”kerberos Authentication Service” /success:enable /failure:enable{/source} Note: You had to activate this on all domain controllers.