Gaia (the underlying OS based on Linux) generates its own logs independent of Access Control and Threat Prevention.
Normally, these logs are kept entirely separate, but can be sent to the same logs that get exported via Log Exporter.
This does not happen by default.
You can set/change that here from the WebUI on the relevant device(s):
Most of the OS logs have completely different context from the things we log with Access Control and Threat Prevention.
As such, all the information from the OS logs is generally put into a single log field.
You can verify this by reviewing the actual log entries in SmartConsole/SmartView.
When those logs are exported via Log Exporter, they likewise end up in a single log field.
In other words, this is working as expected.
If you export syslog directly from the devices themselves to the SIEM, it's possible the information might be parsed differently.