If the connection is using all the time same source port, same source IP, same destination port, same destination IP and same protocol, then the only log connection you see is very first 3-way handshake. Even if it happened 2 months ago, but connection was never removed from connection table.
It is seen for long-lasting services like NTP and syslog. It makes sense as it will kill logserver with heavy log volume for the same connection.
The only way how to see fresh log is to cut the connection from connection table or force the client to use new source port (restart the service).
Kind regards,
Jozko Mrkvicka