Auditing logs really stinks… the QSA’s out there attack a variety of sensitive touch points, and logging is a really tough one to both audit and review properly.
Raffy and the Splunk team have released some new PCI hotness where they make the log requirements 10.6 easily attainable. If you haven’t heard of them, I would encourage you to check them out!