Create an audit policy file for your cluster and pass it to k3s. e.g. –kube-apiserver-arg=‘audit-log-path=/var/lib/rancher/k3s/server/logs/audit-log’
Consider modification of the audit policy in use on the cluster to include these items, at a minimum.