Our security team has asked for us to monitor Event ID 4674 on our Windows SCCM server. However, this is causing... quite a few false positives.

Orion isn't showing the event history (probably overwhelmed), but the admin looked and saw that it was our Orion service account that we use for monitoring AppInsight for SQL causing many of these. The events just indicate that the service account is successfully polling the system, but that makes it look like there is an issue with the system.
Is there a better way to do this? I don't know if we can exclude Windows itself from logging events for a given account, or if we can have Orion filter out those events. Honestly, I am also wondering if there's a better way to monitor for security access to the system, but I'm not sure.