May have answered my own question. I read through the documentation but I never read that you needed to use the "%" to limit your criteria.
Where in the documentation could I find other switches like the % character?
I've found that < .* > works (like regex).
My first experience with Orion's SYSLOG was terrible, but that was using NPM 8.x. It wasn't until around release NPM 9.1 SP5 that I tried it again and it works like a charm.
You probably need to set up any RULE in the Orion interface named SYSLOG VIEWER. This is the area I define all my filtering and it always works and is very stable. I probably have over 500,000 events per day.
The filter choices used in the Orion website view do work but it's just not user-friendly and I feel needs many improvements, not for functionality but for presentation.