Did it work the next day? Or where there any changes in the environment that might have caused that? You can also set --debug 100. As mentioned in the man page, the temporary files created in /var/cache/logwatch will not be removed after the logwatch command completes. Examine those files to see if there are any statements that should have been captured by Logwatch. That debug level will also provide much detail on what is being executed. Remove those temporary files when no longer needed; otherwise...
[systemd] Coalescing start/reload/deactivate statements with different instance IDs.
[sshd] Suppressing output error due to deprecated logging, and
[sendmail] Relabeling incorrect 'error' to 'warning' for STARTTLS summary.
[dovecot] Allow additional 'Info' tag on 'Logged in' statement.
logwatch cron uses erroneous path in newer EL versions.
[logwatch.cron,logwatch.service] Changing executable path to bin.
[fail2ban] Additional correction to force setting of service variable.