Do Syslog agent have the capability to forward already existing logs in the syslog server or it will just forward the logs after installing the agent.
Just the logs after install. What is the use case you are looking to solve with grabbing backwards logs?
The Log Analytics Agent will forward new events per the configuration. This is consistent with a push architecture.
If that doesn't meet your requirements, you can always use the Log Analytics Data Collector here where you can script it to your liking.