its okay I have sorted it now.
For others, get rid of the IPSEC VPN and use a IPSEC Route based. Add Static Route to your syslog server over the Route based ISPEC.
For home setups the syslog will follow the default route 0.0.0.0/0 VIA WAN, so you need the IPSEC VTI interfaces created to you can syslog<ipaddress? via IPSEC VTI
https://docs.opnsense.org/manual/how-tos/ipsec-s2s-route.html
For others, get rid of the IPSEC VPN and use a IPSEC Route based. Add Static Route to your syslog server over the Route based ISPEC.
For home setups the syslog will follow the default route 0.0.0.0/0 VIA WAN, so you need the IPSEC VTI interfaces created to you can syslog<ipaddress? via IPSEC VTI
https://docs.opnsense.org/manual/how-tos/ipsec-s2s-route.html