I've now made a number of changes to rsyslog, resulting in full TCP capabilities. Hopefully, I can make a release announcment today.
With that done, rsyslog is finally on its way to a secure syslog replacement. One of the next steps is to look into using stunnel, a thing that must be easy to do ... but also one that must be set up. The TCP support was a key to using things like stunnel, because UDP packets can not be secured in a way that makes sense (two tunnels would work - but who would like to have such a monster...).