You want to configure syslogd to sort messages according to their levels and/or facilities (such as warn, err, … or security, auth, …). But you do not know the level of the messages.
Unfortunately the normal syslogd has no option for showing level and facility of the messages. But you can configure it in a way that a seperate logfile is kept for each level and each facility. The config file /etc/syslog.conf could look like this:
Now a message with the priority security.warn will be appended to the two files /var/log/lev_warn and /var/log/fac_security.
After having learned all information about the messages, you will probably deactivate those auxiliary log files.
Furthermore, you might want to have a look at syslog-ng, which is a compatible and much more flexible replacement for the standard syslogd.