How to link the generated root token to the revoked token?

As a best practice, we always revoke root tokens once they are used. We want to monitor the audit logs to ensure that if a root token is generated, it is revoked as well. I am not able to find a way to link the 2 log records…already tried accessor_id, hash, client_id etc. Does anyone know of anything that can be used to link 2 logs-generation and revocation?

