Can't audit event 4625

Can't audit event 4625

Event 4625 can alert when VPN users logon failed (my firewall connected to my DC with LDAP).
I found that this event is excluded by Global Exclude rule and I can't remove or edit it.
Is there any way to remove a default Global Exclude rule?