Hi James,
I'm not very familiar with logstash, but you may be interested in looking at Splunk. It's very easy to set up and configure and may not be as picky about formatting. It provides facilities for building your own dashboards and reports by clicking fields you want to watch - less RegEx!
The local0-local7 options are so that you can group filters and log level configurations. If you only want certain sets of data to be sent to a particular target, you can configure that from the switch and then only send that "filtered" data to your syslog target. As you've discovered, you generally only need one of them.
If you do decide to try Splunk, the
Extreme Networks EXOS for Splunk app may also be of interest if your Extreme gear can run EXOS 15.4+. It doesn't analyze "real-time" data, but rather provides an overview of network and device status based on reports through a configurable reporting frequency, part of the EXOS Proactive Service Framework. Full setup instructions are included in the app's readme file.
I hope this helps!
-Drew