I get what you are saying. Although port TCP/443 is a famous port, and it is always being scanned. The reason it would be nice to have an IPS detect log is to know who is actually still trying to exploit after the patch is on. Those IPs in the SKs would be good to look for in the log, but again. My goal to see all exploitation attempts from any IP with an IPS log.
I don't think this is doable for gateways directly attached to the internet, but that is what I was trying to look for.
With all that being said, I think you gave some nice tips and did amazing trying to assist with this 🙂. You deserve a gold star. Thank you.