That means that for each rule you get a different log. Logs only update when new information relevant arrives that's related to a certain rule and all the relevant attributes are the same.
For example: If I have a rule for restricting "Social Media" but I allow anything else. Let's say I surf to YouTube, a log is created and being update with relevant information every few minutes. Then I try to surf to Facebook - I'm getting blocked but this is not updated on the log for YouTube, it creates a different log. Then if I surf to Gmail I also get a new log because it doesn't match the first log in the application name field. If I leave Gmail and return to YouTube, then the log will update again since I'm matching rule and all relevant data in the log, such as application name.
For firewall rules it will work the same, where application name is could be change for service etc.
Kind regards, Amir Senn