I need to look at these later for OSSEC related stuff:
Windows logging
Windows File Auditing
Windows Registry Auditing
Windows PowerShell Logging