When you enable success and failure Audit Privilege Usage auditing, and save a system information file when logged on as an administrator, the following event is logged:

Event Type: Failure Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 578
Date: 12/3/2002
Time: 3:23:33 PM
User: Name \Administrator
Computer: Name
Description:
Privileged object operation:
Object Server: Eventlog
Object Handle: 0
Process ID: 264
Primary User Name: Name
Primary Domain: Name
Primary Logon ID: (0x0,0x3E7)
Client User Name: Administrator
Client Domain: Name
Client Logon ID: (0x0,0x9792)
Privileges: SeSecurityPrivilege
This is expected behavior when using the SeSecurityPriviledge privilege.