I set this all up through the GUI but have looked at the irule possibilities.
My access policy logging is set to debug.
As soon as I add a filter for remote and set the log publisher to remote syslog accordingly
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-external-monitoring-implementations-11-3-0/2.html
If I ad filters for each type of logging and set it to local I get all my local logging back but my remote logging goes away. I don't beleive that having a filter for every local log is the correct way to do it. I must be missing something.