I think all but one of our deployments sends everything to NetSight/XMC/Whatever the new name is. The one customer that doesn’t do that already had some other system running syslog for servers so they chose to send the switch info to that so all their logs would be in the same place.
Are we talking about log filters or syslogging?
Syslogging is definitely a great idea.
If we are talking about log filters. Some times we filter out port delivering power messages or port up/down for copper ports. But I prefer not to filter and just use | to see what I want when looking at the log.