Hey,
It may be possible to import your ESX syslogs. You can try this - on a machine that you have the LEM agent installed on, apply the appropriate ESX syslog connector on that agent (via the LEM web console) & point it to an empty file (e.g. esx.log). Open the empty file & paste your log contents into it. The connector should then parse those logs.
As you mentioned, there are some limitations, mainly the fact that the data will be searched & reported based on Detection Time & the time on the appliance, but the Insertion Time value (original log version) will be collected and shown. The data won't be useful against your rules as it will be too old.
If you are comfortable with sending me a log sample of the exported syslogs, I can then test the above suggestion in my lab & let you know the outcome.