These events should be captured in vRLI. Ensure your agent configuration is set up to forward all the logs and you're not just using syslog. Log entries are going to be your best bet here as I don't believe there's a specific audit trail accessible otherwise for entitlements.