Make sure you have forwarded all the required components to the Log Insight:
1. ESXi Host Logs
2. NSX Manager Logs
3. NSX Controller Logs
4. NSX Edge Logs
Then check if you can see the logs are being forwarded to the Log Insight.
You can refer to this doc (About NSX Logs) on how to specify syslog server for each components
Or these 2 blog postsBayu Wibowo | vExpert NSX, VCIX6-DCV/NV
https://nz.linkedin.com/in/bayupw | twitter @bayupw
Even i have faced this issue in my envornment.
Please configure syslog server "vRLI" ip address in each esx host this should reslove your issue.
Let me know if you are still having this issue we can work on this,
The problema persist. I changed fqdn by IP but not receive events.
Are you able to see all the vSphere components like ESxi host etc.., for me it looks like NSX manger is not sending the logs to the Login sight, when we create a Logical switch or any thing the logs needs to be forward to the Log insight from that log event it takes the number of creation events and mentions on the Login sight dash board.
can you UNconfigure the Syslog server on the NSX manger and reconfigure it.
I am checking the working setup logs to identify the issue.
I will get back to you !
ON NSX manger try to register thhe Syslog details with IP address and select UDP port 514
Forget about the dashboards for a second. In LI, under "Interactive analysis", when you filter on source, do you see anything arriving at all, from all the hosts that you expect (have configured) ?
If that does not work, forget any further steps and fix that first.