No worries. Thats right, it does not give any accounting options in ssl inspection policy. Now, I could be mistaken when I say this, but I believe behavior you see if indeed correct and here is why. Yes, while its true that network feeds use both IPs and fqdns, when it comes to logging, you might not actually see those fqdns in the logs, but with domain object, you usually would, as its either fully qualified domain (by default) or 10 sub-domains if its non fqdn (also by default).
Again, Im not 100% sure about this, but just my logical conclusion based on my previous lab testing as well.
Andy