Event ID 5007 indicates that the current message tracking log file was locked by another process. The System Attendant must be able to write to the current message tracking log file that is found in the Exchsrvr\Tracking.log file. The Event ID 3016 from the Internet Mail Service is logged because the Internet Mail Service is dependent on the System Attendant to actually write to the message tracking log file. The same is true for this event. See ME198733 for details on this issue.
As per Microsoft: "The Microsoft Exchange Server disk could be full or a disk error could have occurred. The message transfer agent (MTA) service will stop if the disk is full". See MSEX2K3DB and the link to "EventID 3016 from source MSExchangeIMC" for additional information on this event.
Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.
Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.