the loggregator team has come across a few cases where in a big cf deployment with over 9k application-bound syslog drains the scalable syslog adapter is reaching its scaling limits (pun intended).
We spent some time rethinking the problem regarding the forwarding of application logs to syslog drains. We came to the conclusion that the forwarding best happens as close to the origin of the logs as possible. To implement that strategy, we want to introduce some process on the diego cell (maybe integrated in the loggregator agent aka metron agent), that will forward each application log line directly to the configured syslog endpoint. You can read more details in this document:
Please let us know if you have any questions or concerns about this approach.