according to the FAQ.. Our software is built and tested to support more than two million messages an hour without tuning. (That would support more than 500 machines each sending one message a second.)
This blog says to split out your busiest syslog source...
But what do you do when a single source exceeds 600-1000 messages per second? eg., upstream syslog aggregator or firewalls