I'm using a Cisco router as my border firewall which is logged to a kiwi syslogd server.
Its not all that flexible...

I can create a script that will exclude certain events from my "reports"...
Maybe that would be a better solution.

I have sofware firewalls that will organize alerts... but thats inside my LAN. If I didn't create the alert... it won't be there. I have yet to see anything other than a false positive on my internal LAN. Unless I created it.