I have recently gotten NTOP-NG running in my environment and am fairly pleased 
with it so far. What I would like to do that I have not been able to find much 
information on is forwarding any alerts from syslog to a syslog collector - 
graylog in my case. I may be able to figure this out on my own but to start 
with I cannot seem to find the location in the filesystem that this is logged 
at. I have the "syslog option" turned on in the preferences but if I search the 
default /var/log/syslog I find no mention of anything generated from ntop at 
all let alone anything related to an alert. That said - if this were ever to 
work I'd really like to not forward the servers entire syslog to graylog and 
parse it down to only what is needed from ntop.

I am running this on Ubuntu 16.04 LTS with the default rsyslog install.

Any suggestions on how to go about this?

