You can collect a LOT of information with LEM from a lot of sources. Maybe it'd be easier if you could specify what you're looking to collect and we can confirm or deny the LEM gets that information?
LEM is a SIEM solution, so it primarily focuses on compliance and auditing information. That means a lot of change management events, authentication events, and other potentially interesting infosec information.