See this post
http://forum.mikrotik.com/t/tool-using-splunk-to-analyse-mikrotik-logs-4-0-graphing-everything/153043/1
Section 2c explains how I do recommend naming the rules.
Select rule to log and see in the log.
If you do use Splunk, it is easy to see what is going on.