Gathering network device data for security detection purposes – Which logs to send to SIEM

For a medium sized organization, what are some of the most important logs that should be sent from Networking Devices (Firewall, internal firewall, routers, F5, PAS, core switches) to the SIEM?

changes in firewall user accounts, logons, and the rule set governing firewall actions.

ddos attacks

software version changes

what else?

Thanks for any guidance

