Cacti core does support adding cacti logs into syslog
However alot of security teams want audit logs sent via syslog
For example Microsoft sentinel or others where its easier to point to a syslog
server for log ingestion then client based agents to read the files on the servers
Security teams may only be interested in the security based events and not application events such as device status and spine results which is why this should be separate
So it would be good to add add an ability for when the audit plugin logs an event to send the event to a designated syslog server