"By Bad and Good behavior I mean that the logs are recognizable to the filtering software -and they don’t…"
Do you mean your Syslog server doesn't show logs at all from the second firewall ?
"I should have receive exactly THE SAME structure of logs from the same device class, same Junos and same configs -do you agree ?"
It might be that they are using different Application ID Engines and definition versions . Can you give us the outputs of the following commands from both firewalls :
> show services application-identification version
> show services application-identification status