When I look at Splunk - where I send my Cisco ACS 5.4 syslog output - I see a record of actions I've done on ACS. But I'm not seeing the TACACS records when I log into various network devices. I can see the tacacs records if I go to Monitoring and Reports section of ACS. How can I view in syslog?
NetworkingSecurityNetworking Hardware-OtherRoutersHardware Firewalls
The link might address it where you specify which events you want logged ...
Another option you could setup snmptrap and send snmptraps to it with events ...