Syslog to AlienVault

Hello,
I’ve been attempting to get some useful events out of Alienvault for about a week now. I have setup syslog forwarding from a couple of our MikroTik systems. The information is being received, but I can’t get any good compliance or firewall reporting (the device type on all of these has been set to “network device:firewall” and “router”. It appears to me that the mikrotik-router.cfg file that attempts to ingest the syslog information is not very good. In most cases it is not correctly creating events with useful properties like category , or sub-category, username, source IP, or source device. I was wondering if anyone has a custom .cfg file and associated sql file they’d be willing to share? Does anyone have any tricks or tips on how they got actionable information out of Alienvault based on the syslog information? Thanks Kevin