If you specify a syslog server, NSX Manager sends all system events to the syslog server.

These messages have a format similar to the message displayed below:

Jan 8 04:35:00 NSXMGR 2017-01-08 04:35:00.422 GMT+00:00  
INFO TaskFrameworkExecutor-18 SystemEventDaoImpl:133 - 
[SystemEvent] Time:'Tue Nov 08 04:35:00.410 GMT+00:00 2016', 
Severity:'High', Event Source:'Security Fabric', Code:'250024', 
Event Message:'The backing EAM agency for this deployment could not be found. 
It is possible that the VC services may still be initializing. 
Please try to resolve the alarm to check existence of the agency. 
In case you have deleted the agency manually, please delete the deployment
 entry from NSX.', Module:'Security Fabric', Universal Object:'false
 

System event contains the following information.

Event ID and Time 
Severity: Possible values include informational, low, medium, major, critical, high.  
Event Source: Source where you should look to resolve the reported event.
Event Code: Unique identifier for the event.
Event Message: Text containing detailed information about the event.
Module: Event component. May be the same as event source. 
Universal Object: Value displayed is True or False.