The Tenshi part of this exercise relies on reverse DNS resolution (because
we are matching logs from hostnames containing 'rtr'), and the source IP
address of the packets will be the router inside IPs.  Hence you need to set
this up, e.g.

$GENERATE 1-9 254.$ IN PTR rtr$.ws.nsrc.org.

The problem with rsyslog permissions is documented at:
https://bugs.launchpad.net/ubuntu/+source/rsyslog/+bug/484336
http://www.gossamer-threads.com/lists/rsyslog/users/3566#3566
