Dears,
you can create a custom rule, and it started logging after I created this rule
<rule id="110047" level="3">
<if_sid>60103,60104</if_sid>
<field name="win.system.eventID">^4688$</field>
<options>no_full_log</options>
<description>A new process has been created </description>