Rahel,
I appreciate your help.
I have used many different documentations, all available from the Juniper support website and KB. And that's the point. There is not ONE document that describes the logging in it's entirety, there are many documents. And they don't reference each other, so things get confusing quickly.
And as you can see by the questions others ask, there is confusion about this topic. Just search the forum for SRX logging, and you will find countless threads, all about the same topic and same questions.
You are saying that maybe customers are not setting up their systems correctly. And exactly that is the point. Why are people setting it up incorrectly? Because they don't know it any better and are confused.
There should be ONE document that describes the logging mechanisms, explains the differences between event mode and stream mode, gives advise an which method to use under which circumstances and how to do it correctly. And it should go deeper than just providing config examples, the document should make people understand.
If Juniper offers such a vast array of logging options AND makes changes to them with basically every new Junos version, then Juniper should make it clear to customers how these work. Right now, as a customer you only have scattered documentation, spread across multiple documents and multiple versions, and they end up coming to the forums, just to find out that people here ask the same questions.
Hence: This is a mess.