You can set the pix to log that event as an alert and check the system log.
logging enable
logging buffered debugging
Now initiate the vpn connection and check the syslog messages in the buffer and see what messages you want to isolate then
logging message syslogid# level 2
logging buffered 2
You also can use an external syslog server and do the same for that (kiwi is a free syslog server or any build of linux) or through the asdm/pdm.
As I recall, tacacs does not do accounting services.
Brent
Systems Engineer / Consultant
CCNP, CCSP