When you enable success and failure Audit Privilege Usage auditing, and save a system information file when logged on as an administrator, the following event is logged:

Event Type: Failure Audit                              Event Source: Security                              Event Category: Privilege Use                               Event ID: 578                              Date: 12/3/2002                              Time: 3:23:33 PM                              User: Name \Administrator                              Computer: Name                              Description:                              Privileged object operation:                              Object Server: Eventlog                              Object Handle: 0                              Process ID: 264                              Primary User Name: Name                              Primary Domain: Name                              Primary Logon ID: (0x0,0x3E7)                              Client User Name: Administrator                              Client Domain: Name                              Client Logon ID: (0x0,0x9792)                              Privileges: SeSecurityPrivilege
This is expected behavior when using the SeSecurityPriviledge privilege.