As for other (non-audit logs), it seems some may be forwarded to syslog. From my experience with (other NetApp apps) and Docker, it's not hard to forward Docker logs to Syslog and from there to a forwarder and/or SIEM, but you'd have to make changes to the OVA file (or possibly StorageGRID appliance configuration) after upgrades. Since these aren't documented, they aren't supported w/o FPVR request by NetApp partner or account team, so you'd still need to get this request done and approved to get the correct instructions and risk-free reapply it after upgrades.
I'll let someone from the SG product team officially comment on that, but you'd still have to parse and transform the audit log file.
One advantage of receiving logs via syslog would be near real-time logs. Compared to that, re-reading audit.log from NFS is possible but due to log file size it couldn't be done very frequently (maybe once an hour?) because the file can be large. It's probably more reasonable to check the share every X hours and deal with log files only after they've been rotated (i.e. they won't be updated, so they won't need to be re-read either). I know it's not the solution you want but I don't know of any other.