Thanks to both but could you please explain
1- If I want to check the logs for a particular policy how can I do it? Because log file capturing RT_FLOW_SESSION would show logs for all policies
2- If I want to send the logs to NSM, Kindly correct me if I understand correctly. If mode is event under [security log] then following lines are essential:
set system syslog file default-log-messages any any
set system syslog file default-log-messages structured-data
BUT If mode is stream under [security log] then above lines no need?
Thanks