Found it. On the SolarWinds server, open Syslog and SNMP Traps > Syslog Viewer. Navigate to View > Alerts/Filter Rules. Click on the Alerts/Filter Rules tab. Add a new rule that matches on the DNS name of the ASA. On the Message tab, enter *AAA user authentication*. On the severity/Facility tab, check Informational and select all under the facility. Create the alert action that you want, then hit OK all the way out. That did the trick for me.