I will add that for Windows WireShark offers a convenient syslog viewer, ironically. I tried several other syslog tools, and indeed, Kiwi is the best for syslog, but the "free" version is a little nervous. Others that I encountered were either poorly programmed (logview4net failed for minor problems), had a bad interface (Star SysLog Daemon Lite), or did not even start (nxlog)
You can use the WireShark filter language to drill down on log data. This is too complicated, but until someone writes a free syslog viewer / collector for Windows and makes it decent, this is one field that will be difficult for most people.
Example:
# Display level 6 alerts from 192.168.5.90 in WireShark syslog.level == 6 && ip.addr == 192.168.5.90
Kumba Oct 30 '11 at 3:11 2011-10-30 03:11
source share