Rancher Audit logs to Splunk / Graylog

Hi All,

We are moving Rancher to Production and one of the action item is to maintain Rancher audit logs in splunk / Graylog.

Can we do that by mentioning docker log driver as syslog when booting up Rancher server?

I saw in Rancher documentation that we need to call API to get logs. Any alternative approach possible?