The local syslog server needs to have access to the Certificate Authority (CA) trusted certificate used to generate the certificates for the remote syslog server.
Go to your Primary EPM Server.
Open the vi /etc/rsyslog.conf file.
In the rsyslog.conf file, place the certificate in the default location as shown below: