Security Settings\Local Policies\Audit Policy are:
Audit account management
Audit directory service access
Audit logon events
Audit object access
Audit policy change
Audit privilege use
Audit process tracking
Audit system events
Enable the Audit object access
secpol.msc -> Local Policies -> Audit Policy -> "Audit object access Properties"
i.e.:
Delete Event
Object Access
EventID 560