There are actually several formats supported by Log Exporter.
Many of them are SIEM specific, but standard rsyslog and ng-syslog are both supported targets.
Refer to:
If you send syslog from a gateway, you will only get firewall logs (no logs for App Control, URL Filtering, or Threat Prevention blades).
The only way to get complete log data is to have data sent from the management.
While it is supported to send syslogs from the gateway, it's generally not recommended for that reason.