As per Microsoft: "In certain situations, the Queue Manager attempts to initialize auditing in the context of the calling process, but the Queue Manager does not have sufficient permissions to do this". See ME311389 for a hotfix.
Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.
Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.