[UPDATE] - not resolved by normal means, but I installed a Splunk Forwarder agent and I am currently forwarding /var/log/filter.log to my Splunk servers directly, in real-time.
A band-aide job for sure, but still very puzzling why /var/log/filter.log is not being sent when others are.
A band-aide job for sure, but still very puzzling why /var/log/filter.log is not being sent when others are.