cisco-asa rules dont work when changing syslog logging levels
all cisco pix/asa syslog messages begin with a prefix like this:
it is possible to change the logging level of alerts so that, for example, a message that is normally informational (level 6) will be displayed at the warning level (level 4). this changes the logging_level part of the message prefix. unfortunately, this causes the current cisco rules to stop working, because they depend on the default logging_level. the rules should not care about the logging_level, as it is user-configurable on the pix itself (this is probably true for cisco routers and switches as well).