NIDS are different from log systems as they are more focused on network traffic and events. Some systems can also handle classic syslogs. NDIS systems are typically feeders for SIEM systems.
PS: often Snort is used for packet inspection while Sagan is for syslog.