The configuration for WinRM contains security descriptor string that is used to control access to resources using WinRM and the WS-Management protocol (run 'winrm configsddl -?' for details on how to modify this property). When this SDDL is changed so that audit messages should be logged when a user accesses a resource, those messages are not generated in the event log when running on Windows XP.
There is no known workaround for this issue on Windows XP.