This is not what I'm after.
That SK outlines how to 'How to configure Security Gateway on Gaia OS to send FireWall logs to an external Syslog server'.
I'm already sending firewall logs from all gateways to remote log servers, and from there using log exporter to send in to Splunk.
I'm referring specifically to configuring syslog on individual gateways to send Gaia system messages and audit events only to a remote syslog server. And we want to send this to the remote server on a custom port.
It's interesting that SK also states at the bottom of the document that the fwsyslog_enable parameters is "is intended for optimization of logging performance in environments that require high log rates.Do not enable this kernel parameter unless explicitly instructed by Check Point Support.", as there is no mention of that in the Logging and Monitoring R80.20 Administration Guide, > Logging > Working with Syslog Servers section.