1) Go to Syslog page, add two alert rule, one individual, on threshold type and trigger it 2) Go to Syslog - Alert log page, choose device filter as local hostname, show incorrect info --failed 3) Choose device filter as Threshold logs, show correct info -- pass 4) Choose device filter as All, can show correct info -- pass 5) Choose device filter as Threshold and local hostname, device filter change to selected 1, but show both info --failed Expect behavior: Can show correct record when change device filter Can select multiple device and show correct info     
Expect behavior:
Can show correct record when change device filter
Can select multiple device and show correct info