Hi there,
"class" knob does work in 10.4 but is hidden so you have to type it in full when entering it via CLI.
If you cannot afford to use hidden JUNOS knobs, then you can achieve per-flow syslogging by configuring "then syslog" under each stateful-firewall rule term.
Also, I just noticed that you have configured to syslog only "info" severity events from MSDPC.
If your "messages" file is not configured to accept "info" severity events, you can miss MSDPC syslog.
Please check what cutoff severity is configured under [edit system syslog file messages].
HTH
Rgds
Alex