Hi Jo3rg,
Maybe not a definitive answer, but I would assume you are sending logs to a syslog server.
You could possible install the check_mk agent and logwatch plugin on the syslog server. Then configure /etc/check_mk/logwatch.cfg to monitor normal text files for Error/Warning/Down …
You can also send syslogs logs directly to Check_MK Event Console and create rules to alert, but not used this method myself yet. (Job to do)
I’m sure someone else can add to the discussion.
HTH
Andy