See also our paper presented at the 2001 Usenix Annual Technical Conference, available in the proceedings or at http://www.usenix.org/publications/library/proceedings/usenix01/freenix01/westerlund.html.
There are lots of texts about Kerberos on Microsoft's web site, here is a short list of the interesting documents that we have managed to find.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters\LogLevel
with value DWORD equal to 1, and then you'll get logging in the Event
Logger.
Other useful programs include these: