I am wondering what are the pros and cons of the following two logging setups:
Would appreciate if anyone can share his/her experience. Thanks.
It depends for which logs. I prefer the forwarder for it's flexibility, but syslog has a lower footprint.
Additionally, you can throttle bandwidth for sending logs over WAN network using Forwarder which is not otherwise possible.
And the forwarder can do WinEventLogs far nicer, at least compared to snare. In fact, if there are multi-line log messages, I'd say that's a sign to go with a forwarder.