For SQL Server audit information, we ended up sending the data to the wineventlog index as application events.
This data - EventCode=33205 should be visible only for the cyber/audit audience. How can we apply a different access to this data or should we route it to a different index? If so, how can we do it?