I did a workaround. And yes I do think McAfee is the culprit.
I forwarded events from the domain controller to a syslog server and then sent them on to a second server. That helped and now I can log all I ever wanted and all I ever needed
Thanks for the input and help