It is mainly used to collect various event logs from multiple machines and transfer them to the syslogviewer dedicated server for users to view and review.... It can be used on UNIX and Linux type ...
A common scenario is to have a centralized SIEM based on syslog. The best option is for the SIEM to integrate directly with Azure monitor (Splunk, IBM QRadar, ArcSight...). If that is not available ...