Chris, I've done the same thing with a centralized syslog. One danger with a combined log is having OSSEC attribute all the log entries to the syslog server, and not to the actual agent. Check your decoder rules to make sure they're parsing the records correctly.
- Dave
