Hello @Krzysztof Madej
Welcome to Microsoft Q&A Platform.
Firewall logs are based in the Rule ID of the triggering event so if the rule is disabled it won't appear in the logs:
https://video2.skills-academy.com/en-us/azure/web-application-firewall/ag/web-application-firewall-logs#firewall-log
If you think that this feature would be useful you can raise a request via Azure Feedback portal:
https://feedback.azure.com/d365community/forum/8ae9bf04-8326-ec11-b6e6-000d3a4f0789
I hope this helps!
----------
Please don’t forget to "Accept the answer" and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.