Say what you are trying to establish. This gives you the sources that would establish it, in the order to collect them, with the ones that expire first at the top, and the source people commonly reach for that does not actually settle the question.
A legitimate account was used by an unauthorised person.
Collect first, these expire. The Security event log is 20MB by default and holds every authentication on the host. On a domain controller assume hours, not days.
does not proveAnything launched from a console, a script, a service or a scheduled task — this is GUI activity only, so most attacker tooling is absent
A successful logon. It shows authentication, never who was at the keyboard. Behaviour after the logon, UserAssist and ShellBags for that profile, is what separates the account owner from somebody wearing their credentials.
if you find nothing
Impossible-travel and out-of-hours patterns need a baseline. Pull a normal week for the same account before deciding anything looks unusual.
Worked a case where this list was wrong or incomplete? That is worth more than the list is. Say so.