To clarify a bit, if you set up the MX to send syslog to a syslog receiver, it will source that traffic from the highest #'d VLAN interface defined on the MX. So, if you have a couple interfaces defined like so:
VLAN 10 - 10.10.10.0/24
VLAN 20 - 10.10.20.0/24
VLAN 30 - 10.10.30.0/24
The syslog traffic will source from the VLAN 30 interface, 10.10.30.1.
If at any point you add VLAN 40 - 10.10.40.0/24, the syslog will then come from 10.10.40.1.
If the site-to-site VPN/Meraki AutoVPN is in play, the syslog will source from the highest #'d VLAN participating in the VPN