Syslog critical messages not showing ?

We are seeing an issue with seeing Sev5 alerts coming from devices that are sending error messages to the logging database. 

specifically, we are looking for OSPF neighbor state changes that we see going out on packet cap, but they don't seem to make it to the database, although other messages are. 

Could we be filtering them out in some way that we don't see ?