Hello
I got your private messages. Private messages wont show up here, you have to reply all before you can see it in the thread.
To the main issue, setting them to no will not stop your logs from ingesting, it only means they won't write to archives any longer, which in turn saves you storage space, because with logall/logall_json set to yes, it means all logs, whether they match a rule or not, will be written to that file, and it consumes space and could cause disk performance issues in the future. So we always advice you set those to no.
If they are on no, you will be able to get an alert so far as the logs match any rule. The configuration is useful at the initial stage when you are still trying to map logs to rule and filter for noise.
That said, you are yet to share the sample log requested from archives.json file, this will help me understand how the logs are ingested and to properly map them to a rule. You can send them privately as you initially did.
Regards,