This is a self-explanatory event. If your DNS server is of "Standard Secondary" type, it requests the new version of the authoritative zone from the Master DNS server. This can be inititated in two ways:
1. Your DNS server is checking periodically the version of the SOA record on the primary and if it is found larger than the last time, the server requests a zone transfer.
2. Instantly after a zone change, if you use DNS notify on the primary server.
Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.
Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.