The docs say in the new Log Analyzer, you can tag syslogs, but I don't seem to have that option in any of the various locations I can configure rules. This is all I get:
Pre-processing

Syslog

It looks like I should be able to do this, according to this page. I tried looking in the Log and Event Settings and there doesn't seem to be a setting that explicitly enables or disables this feature.