Security Log Best Practice



I have 3 W3K DC's. I want to set the Security event log settings via
GPO. what is a best practice for event log settings? one question I
have is now I have one that is set for 4096kb and overwrite as
needed , but the size is 128 meg. another DC is set for 4096kb and is
now at a size of 16meg. how can these grow past the stated size.

thanks in advance.
Rick

.