I don't know about aggregating syslog on a machine and using osquery to send it to AWS... The osquery events system wasn't really designed to scale to that volume. The syslog_events table was designed for forwarding the local syslog. You can of course have each machine write its local syslog to AWS.