Hello Ondrej Vendég,
Thank you for posting in Microsoft Community forum.
You can add the domain user or domain group to local Event Log Readers group on every domain machine.
If you have more than one machine, you can add the domain user or domain group to local Event Log Readers group on every domain machine via GPO.
1.Create one OU and put these machines to this OU.
2.Create a GPO.
3.Link this GPO to OU above.
4.Edit the GPO. Navigate to Computer Configuration\Preferences\Control Panel Settings\Local users and groups\New Local Group
Group Name: Event Log Readers (built-in)
Members: add the user or group you want.
Reference:
I hope the information above is helpful.
If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou