Yes all traffic that has the logging enabled will be sent to the syslog server.
Inside the syslog the rule is identified via the ''pattern'' eg :
pattern: allow tcp && (dst 20.0.0.0/8 || dst 30.0.0.0/8 dst port 1234)
Adding a rule ID or rule name would have been way simplier , but hey 🙄