can the firewall rules logs identify which rule logged the event allow or deny?
Yes whether you have it set to Deny or Allow. The Event Log will note it. So if you have Deny outbound for facebook.com it will show DENY Source IP/Port and Dest IP/Port. Vice Versa if you have it set to allow: ALLOWED Source IP/Port and Dest IP/Port.