Help grokking a syslog

Hi @NerdSec, so the idea is to start with a "loose" filter, then continue filter with more and more detail until you capture every possible scenario?