To log Syslog packets to a database, click the "Syslog to Database" tab and add one or more databases to the list of databases by clicking the "Add" button.
By default, all Syslog messages received will be sent to the specified database(s). To change this behavior, you can either exclude certain messages from being added to the database (include all, exclude some), or only send specific Syslog messages to the database. Click the + icon to add strings that will include or exclude Syslog messages.
Include: Log all Syslog messages to the database, except for exclusions below
This is the default setting, and it will send all Syslog messages to the database. Syslog messages containing strings that are listed below will not be sent to the database. This allows you to conserve space in the database by filtering out unneeded Syslog messages.
Exclude: Only log Syslog messages to the database that are included below
This setting is more restrictive and will only send Syslog messages to the database that are listed below. This allows you to only send messages to the database that match your filters.
For more details on the filter syntax see the "Syslog to Event Log" chapter. Don't forget to add a heading and/or trailing asterisk if you are specifying a partial string match.