@RT-7199 , Thank you for the detailed information in the question.
Based on the information, you have added "Microsoft Monitoring Agent" (also know as MMA, Log Analytics Agent or LA agent). It is by design that you cannot see the security event in the LA workspace when using this agent. See the Important section in the following link for more details - Configure Windows event logs.
Therefore, to collect the security event logs, you must use Microsoft Defender for Cloud or Microsoft Sentinel
Alternatively, you can migrate the monitoring from this agent to newer Azure Monitor Agent where you can configure Data collection rules for collecting security event logs. Note that the Microsoft Monitoring Agent (LA Agent) will be retired by August 31, 2024. Therefore, I would recommend to start planning the migration from legacy MMA to newer AMA. For more details, see Migrate to Azure Monitor Agent from Log Analytics agent
Please let me know if you have any questions.
If the aswer did not help, please add more context/followup question for it, and we will help you out, else please click Accept answer so that it can help others in the community looking for help on similar topics.