The user "NACUser-ACL" is the one that you are trying to filter out? If that is the correct spelling of the user, it should filter if you add it to "Users to Ignore for Chagne Detection".
Yes, the patterns defined are text and they are searched for through the whole syslog message. However, regex is allowed as well, as you can see when looking at the default patterns in the Change Detection section of Administrative Settings.
If this doesn't give you what you need, then I would suggest going to Admin/Troubleshooting and setting "external/syslog" to trace and then making a test change on the device.
I would give it some time, or if you see a snapshot, then download troubleshooting with 4 wrapper files and Administrative settings checked.
Then we can look at the logs and see how the syslog message is formatted.
Online outReach Resource HP Support
The views and opinions expressed in my contributions are my own and do not necessarily reflect the views and strategy of HP
If you find that this or any other post resolves your issue, please be sure to mark it as an accepted solution. If you are satisfied with anyone’s response please remember to give them a KUDOS by clicking on the STAR at the bottom left of the post and show your appreciation.