On my ossec server, i'm using rsyslogd for central syslog server. Config file is:
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading local decoder file.
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'rules_config.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'pam_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'sshd_rules.xml'
2013/10/31 14:04:59 ossec-remoted: INFO: Started (pid: 12844).
2013/10/31 14:04:59 ossec-remoted: Remote syslog allowed from: '
221.133.0.0/28'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'telnetd_rules.xml'
2013/10/31 14:04:59 ossec-remoted: INFO: Started (pid: 12845).
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'syslog_rules.xml'
2013/10/31 14:04:59 ossec-remoted: INFO: Started (pid: 12846).
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'arpwatch_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'symantec-av_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'symantec-ws_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'pix_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'named_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'smbd_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'vsftpd_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'pure-ftpd_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'proftpd_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'ms_ftpd_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'ftpd_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'hordeimp_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'roundcube_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'wordpress_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'cimserver_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'vpopmail_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'vmpop3d_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'courier_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'web_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'web_appsec_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'apache_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'nginx_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'php_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'mysql_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'postgresql_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'ids_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'squid_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'firewall_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'cisco-ios_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'netscreenfw_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'sonicwall_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'postfix_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'sendmail_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'imapd_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'mailscanner_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'dovecot_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'ms-exchange_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'racoon_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'vpn_concentrator_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'spamd_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'msauth_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'mcafee_av_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'trend-osce_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'ms-se_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'zeus_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'solaris_bsm_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'vmware_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'ms_dhcp_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'asterisk_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'ossec_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'attack_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'openbsd_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'clam_av_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'bro-ids_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'dropbear_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Reading rules file: 'local_rules.xml'
2013/10/31 14:04:59 ossec-analysisd: INFO: Total rules enabled: '1289'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/mtab'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/mnttab'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/hosts.deny'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/mail/statistics'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/random-seed'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/adjtime'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/httpd/logs'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/utmpx'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/wtmpx'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/cups/certs'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/dumpdates'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: '/etc/svc/volatile'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/System32/LogFiles'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/Debug'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/WindowsUpdate.log'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/iis6.log'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/system32/wbem/Logs'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/system32/wbem/Repository'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/Prefetch'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/PCHEALTH/HELPCTR/DataColl'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/SoftwareDistribution'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/Temp'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/system32/config'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/system32/spool'
2013/10/31 14:04:59 ossec-analysisd: INFO: Ignoring file: 'C:\WINDOWS/system32/CatRoot'
2013/10/31 14:04:59 ossec-analysisd: INFO: White listing IP: '127.0.0.1'
2013/10/31 14:04:59 ossec-analysisd: INFO: White listing IP: '192.168.1.111'
2013/10/31 14:04:59 ossec-analysisd: INFO: White listing IP: '192.168.1.112'
2013/10/31 14:04:59 ossec-analysisd: INFO: 3 IPs in the white list for active response.
2013/10/31 14:04:59 ossec-analysisd: INFO: White listing Hostname: 'localhost.localdomain'
2013/10/31 14:04:59 ossec-analysisd: INFO: 1 Hostname(s) in the white list for active response.
2013/10/31 14:04:59 ossec-analysisd: INFO: Started (pid: 12836).
2013/10/31 14:05:00 ossec-remoted(4111): INFO: Maximum number of agents allowed: '256'.
2013/10/31 14:05:00 ossec-remoted(1410): INFO: Reading authentication keys file.
2013/10/31 14:05:00 ossec-remoted: INFO: Assigning counter for agent myagent: '39:897'.
2013/10/31 14:05:00 ossec-remoted: INFO: Assigning sender counter: 0:517
2013/10/31 14:05:00 ossec-monitord: INFO: Started (pid: 12856).
2013/10/31 14:05:02 ossec-analysisd: INFO: Connected to '/queue/alerts/ar' (active-response queue)
2013/10/31 14:05:02 ossec-analysisd: INFO: Connected to '/queue/alerts/execq' (exec queue)
2013/10/31 14:05:04 ossec-syscheckd: INFO: Started (pid: 12852).
2013/10/31 14:05:04 ossec-rootcheck: INFO: Started (pid: 12852).
2013/10/31 14:05:04 ossec-syscheckd: INFO: Monitoring directory: '/etc'.
2013/10/31 14:05:04 ossec-syscheckd: INFO: Monitoring directory: '/usr/bin'.
2013/10/31 14:05:04 ossec-syscheckd: INFO: Monitoring directory: '/usr/sbin'.
2013/10/31 14:05:04 ossec-syscheckd: INFO: Monitoring directory: '/bin'.
2013/10/31 14:05:04 ossec-syscheckd: INFO: Monitoring directory: '/sbin'.
2013/10/31 14:05:05 ossec-logcollector(1950): INFO: Analyzing file: '/var/log/messages'.
2013/10/31 14:05:05 ossec-logcollector(1950): INFO: Analyzing file: '/var/log/secure'.
2013/10/31 14:05:05 ossec-logcollector(1950): INFO: Analyzing file: '/var/log/syslog'.
2013/10/31 14:05:05 ossec-logcollector(1950): INFO: Analyzing file: '/var/log/xferlog'.
2013/10/31 14:05:05 ossec-logcollector(1950): INFO: Analyzing file: '/var/log/maillog'.
2013/10/31 14:05:05 ossec-logcollector(1950): INFO: Analyzing file: '/var/log/httpd/error_log'.
2013/10/31 14:05:05 ossec-logcollector(1950): INFO: Analyzing file: '/var/log/httpd/access_log'.
2013/10/31 14:05:05 ossec-logcollector: INFO: Monitoring output of command(360): df -h
2013/10/31 14:05:05 ossec-logcollector: INFO: Monitoring full output of command(360): netstat -tan |grep LISTEN |grep -v 127.0.0.1 | sort
2013/10/31 14:05:05 ossec-logcollector: INFO: Monitoring full output of command(360): last -n 5
2013/10/31 14:05:05 ossec-logcollector: INFO: Started (pid: 12840).
2013/10/31 14:05:06 ossec-dbd: INFO: Started (pid: 12819).
Best Regards,.