OK, this makes sense then. Log Insight only attempts to resolve the source field of events and not the hostname. If the hostname is/was IP and now is/was FQDN then this typically indicates a configuration change on the originator of the event or a configuration change on a syslog aggregator if applicable. Syslog agents can be configured to send the hostname field as either IP or FQDN. Syslog agents may also look at settings such as those defined in /etc/hostname and/or /etc/hosts when starting to determine how to set the hostname field.
What OS and what syslog agent are you using? Is it possible a configuration change occurred?