I sell RDP slots on servers running windows 2012 which is much the same as windows 8

I also sell admin plans
DUMB I know but the fact is they are one of my best selling plans

but controlling admin users is a pain
im just starting to learn how to use the Event-logs to track down abusers
but im not sure what to search for

for instance I need to track down who is making new user accounts
and also who is rebooting the server
and who is deleting folders in the Clients drive