As a Change Auditor Administrator, I'd like to audit the success/failure of granting Kerberos Service Tickets. Windows Security Log event ID equivalent 4768 and 4769.
Change Auditor includes “Authentication Services” and “Logon Activity” event classes that should monitor Kerberos authentications, covering both TGT (Ticket Granting Ticket) and TGS (Ticket Granting Service) event IDs 4768 and 4769. However, you will need to have the Logon Activity license as a requirement so that these events can be captured: