I opened a ticket on this, but I'm curious to see if anyone else is noticing this problem. I am using the Syslog Server pretty extensively for message storage and alerting. I've noticed a couple months ago that the messages were not being stored in the database properly. Messages will get stored with the wrong Message Type or store incorrect (or non-existent) FirstIP, SecondIP, ThirdIP data in those columns. For instance, I could have an SEC-AUTH message come in regarding a login to a Linux server, but it will be stored with Message Type PIX-xxxxxx, or a LINK-UPDOWN Type. This really screws around with our alerting.
Is anyone else noticing this and perhaps having the same problem? I was really hoping it would be fixed in 8.1, as my ticket was opened in late April. I've not gotten any updates on if/when it would be fixed.