Hi, and welcome to the User BB!
The syntax to use is REGEX. If you look in the actual Firewall log file, you will see that your filter term needs to be fwrule="1" instead of Packet filter rule #1.
Also, when posting a line from the firewall log, use the line from the full Firewall log file. Unlike the other Live Logs, the Firewall Live Log omits the details needed to analyze a problem.
Cheers - Bob
This is the first I've seen your post, btank. You want Packetfilter logfiles on the Sophos UTM - Sophos Community.
I don't know of a way to use operators in the searches done from within WebAdmin. If you need to use them, you'll have to go to the command line.
Cheers - Bob