As per Microsoft: "This event is logged to inform you that, in response to a user-initiated action, this host will stop accepting new network traffic. When there are no more active connections, this host will stop its cluster operations". See ME897654 and MSW2KDB for additional information about this event.
Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.
Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.