The administration manual states that for syslog:
20.1.2.2 Limitations
The log forwarding of cached logs in not supported for Identity Server and ESP events.
The failover mechanism communication does not work in Access Gateway.

The manual then discusses configuring Caching of Audit events.
20.1.2.3 Caching Audit Events
By default, the local syslog agents do not cache or queue the audit events when the remote syslog
audit server is not reachable. This results in the loss of audit events. It is recommended to enable
cashing for audit events in the local syslog agent.
On Linux, you can make use of the rsylsogs queuing feature for caching the audit events.
A sample configuration for caching the audit event is as follows:
$WorkDirectory /rsyslog/work
$ActionQueueType LinkedList
$ActionQueueFileName example_fwd
$ActionResumeRetryCount -1
$ActionQueueSaveOnShutdown on

I'm trying to test caching of events on the Access gateway using rsyslog. If the remote rsyslog instance is up, events are forwarded.
If I shut it down, I don't see anything saved to the local $Workdirectory and nothing is forwarded when rsyslog is restarted on the remote server, the events are lost.

Any tips as to what I might be missing? Are the "limitations" listed above the reason this does not work?
thanks in advance...