Logging login failure to splunk


I’m using keycloak on openshift, logging to splunk.
Login failures get logged as events to the keycloak admin console (save events activated).

Keycloak logging level is set to WARN.
But only KC-SERVICES0053 is added as log entry in splunk.
KC-SERVICES0013 is missing in splunk.

Where is my misconfiguration?