If you specify a syslog server, NSX Manager sends all system events to the syslog server. Each message has the following format:

syslog header (timestamp + hostname + sysmgr/)
Timestamp (from the service) 
Name/value pairs 
Name and value separated by delimiter '::' (double colons) 
Each name/value pair separated by delimiter ';;' (double semi-colons) 

The fields and types of the system event contain the following information.

Event ID :: 32 bit unsigned integer  
Timestamp :: 32 bit unsigned integer  
Application Name :: string  
Application Submodule :: string  
Application Profile :: string  
Event Code :: integer
Severity :: string (possible values: INFORMATIONAL, LOW, MEDIUM, MAJOR, CRITICAL, HIGH)  
Message ::