Your choices are
- nxlog - it's awesome.
- rsyslog built for windows - it's rsyslog, but built for windows
- some ridiculously rube-goldbergian mess that requires you set up an entire ecosystem and get a PhD to get properly configured with your 3 new staff members.
Both use code from rsyslog, listen on 514 (configurable) and do logging. I think they'll even take mqtt and json-format stuff, but I wasn't needing that yet so I didn't care
Full disclosure: I first started looking into this at my last post, a mere 600 boxes for windows, which I don't do and didn't care about except some log guy was a splunk fanboy dick and I punked him as often as I could because splunk's absolute inability to cope pissed me off and thus he did by association -- thus the mqtt angle as I tried to push that transport idea through because splunk has no clue anymore and can't cope with mqtt and I liked to see his brain reboot. I'm a Linux/Unix guy so I mainly quote on things that will bring the oddballs into line. My new spot has like 3600 winboxes and I just heard that group's choice for shipping logs to the central log correlation is ...
... Nxlog.
Grain of salt, but good luck.