Currently, when customer has an export server configured for Netreo to send Audit logs, we send the syslogs using UDP port 514.
Having control over the port will allow to send logs to a Splunk server that uses different indices for different types of traffic. For exapmle, port 30516/UDP.