Rancher Audit logs to Splunk / Graylog

Hi All,

We are moving Rancher to Production and one of the action item is to maintain Rancher audit logs in splunk / Graylog.

Can we do that by mentioning docker log driver as syslog when booting up Rancher server?

I saw in Rancher documentation that we need to call API to get logs. Any alternative approach possible?

https://rancher.com/docs/rancher/v1.3/en/api/v2-beta/api-resources/auditLog/

Thanks,
Vishnu