Create a 'user' account in your Active Directory and configure ADAudit Plus Service / Domain Settings Page with this 'user' account for data collection, processing and report generation.
Open GPMC | Create a new GPO for the domain | Add the "Domain Controllers, Member Servers, File Servers & Workstations" that require audit into the Security Filtering settings of this Group Policy Object.
Add the user in 'Manage auditing and security log' policy; this setting can be found under Computer Configuration | Windows Settings | Security Settings | Local Policies | User Rights Assignment | ; Use the newly created GPO and push this setting to all audited Servers.
For Domain Controllers above 2003: Open Active Directory Users and Computers | Builtin Container | Add user as a member of 'Event Log Readers' group.
The 'user' must have the DCOM & WMI permission only for the Windows Failover Cluster configuration.
Open Active Directory Users and Computers | Users Container | Add user as a member of 'Group Policy Creator Owners' group
Open Local Users and Groups | Groups | Add user as a member of 'Local Administrators' group (On Every Monitored File Server for File Server Auditing).