We had a customer that needed to make use of the audit trail in Cloud but found no events, then we found it was not enabled after checking the configure audit trail documentation.
They don't think it is very likely that someone with administrative access would have found and disabled it on purpose or by accident.
All the boxes below were unchecked on the Everyone user. Is this something need to be manually enabled for cloud systems. Often people don't know they need audit trail until something unexpected happens.