You have to navigate to
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options
And configure Network Security: Restrict NTLM: Audit NTLM authentication in this domain
Log files will be on operational event log under Applications and Services Log\Microsoft\Windows\NTLM in the Event Viewer.