You can configure a syslog server under the zone settings (Open the zone configuration and you will find a "syslog" section. There you can specify an external syslog server where the APs will send the syslog data directly without passing by the controller (the controller still receives alarms, events, etc though)
This is where I had configured that option - in the Zone config. Pointed to external syslog ( splunk ). were searching hostname in splunk and found the APs are actually identified by IP Address in the syslog updates.
Also noted that the format of log data is much different between the controller and the AP.