I set up the following selection criteria in a filter to drop syslog for low level syslog frfor 2 class "B" networks
10.70.0.0/16, 10.73.0.0/16
10.73.0.0/16 are still getting through and processed bug?
I agree with lchance. Split them into two seperate filters. For the Alert Actions, are you simply stating, "Discard the syslog Message"?
i don't have any rules with Subnet Lists like you have.
have you tried to split these into two seperate rules. if it works then, then i would say yes bug!