I think the decision lies in what you are more comfortable with and what you may already have setup. The users who are upgrading from previous versions that already have events databases configured may stay with that where as someone who is new and has existing syslog infrastructure may opt for that method.
↧