If you have grown out of your syslog database, it is time to use KiWI Syslog instead. I originally was sending my Firewall events to my syslog server along with my network device syslog events, and found out quickly this is not a good idea. Depending on the number of events you may need a seperate Syslog Server for Firewall Events and use the builtin NPM syslog for your network devices only. Also you should look at the amount of time you are keeping the syslog events.