Thanks for the follow up. We're in the middle of a DDOS attack (off and on for days now) so I'll have to look back into this when I have a bit more time.
The attack is why I was trying to get this to work in the first place.
We have since purchased a new firewall which is a little more capable in terms of reporting, so our immediate need for logging is somewhat less than it was.
Thanks,
-E