Forward selected log facilities to an off-box collector (a managed block in /etc/syslog.conf). UDP (@host), TCP (@tcp://host:port) and TLS (@tls://host) are supported. TLS verifies the collector certificate against the system CA bundle by default; a custom CA and a mutual-TLS client certificate can be configured below.