Discussion moved from Community Interface Help to Security Information and Event Management (SIEM) for better support.
Possible changes to your Data Source configuration to resolve the issue:
Set the Mask to '32'
Set Support Generic Syslogs to 'Log "unknown syslog" event'
If you are using a Radius/TACACS Server for AAA you may see system changes from that Data Source.
You can use the TCPDUMP from the Event Receiver to verify you are receiving the logs. (tcpdump src xx.xx.xx.xx)
You can also try enabling "Auto Learn" and configre "Auto adding data sources" on the Receiver.